# Indirect Prompt Injection in MCP

Indirect prompt injection in MCP hides instructions in form fields, email, and tool results. What the host must still check in code.

Author: Formgong team
Published: 2026-10-06
Updated: 2026-10-06
Language: en
Canonical: https://formgong.com/en/blog/indirect-prompt-injection-mcp/

Indirect prompt injection in MCP is untrusted text that a model treats as an instruction. That text can be a stored form field, an email, a chat copy, or a tool result. Direct injection is typed into the chat. Limit tools, encode output, and require a person before a side effect.

## What is indirect prompt injection in MCP?

**TL;DR.** Indirect prompt injection in MCP is a stored form field, an email, or a tool result that a model treats as an instruction. The sketch below is a placeholder, not a payload: the form is stored, an MCP tool returns it, and the agent proposes a send. Stop that send in code. A phrase filter does not. Limit the tool, check its arguments, and require a person before a side effect.

**Series note.** [How do HTML forms work? The HTTP request](/en/blog/how-html-forms-work-low-level/) stops when a field map exists. [Types of Injection Attacks on Web Forms (2026)](/en/blog/injection-taxonomy-2024-2026/) names the interpreters that map can reach. This article is the model and the tool. Setup for a plain page stays on [HTML contact forms](/en/for/html/).

Indirect prompt injection in MCP is untrusted text that a model treats as an instruction. The text is copied in from a form field, an email, a chat message, or a tool result. The protocol does not stop that. The host and the tools have to.

Picture a contact form. The visitor fills name, email, and message. The backend stores the map and emails you. So far the message is text. Later you ask an assistant to summarize new leads. That assistant can also send mail and write a spreadsheet. The same message is now inside the prompt. A sentence in it can be treated as the next step, not as a note from a stranger.

That is the whole bug. [Types of Injection Attacks on Web Forms (2026)](/en/blog/injection-taxonomy-2024-2026/) calls injection a field parsed as instructions. Here the interpreter is a language model. The Model Context Protocol, MCP, adds a cousin in the tool list. That case is on [what tool poisoning in MCP is, with a scanner you can run](/en/blog/mcp-tool-poisoning/).

This page stays defensive. It names goals, boundaries, and controls. The worked example uses a placeholder sentence, not a payload. It does not include poisoned tool samples or steps you could drop into an agent. Primary sources were fetched again on 06.10.2026.

We build [Formgong](/en/). Product notes below match the code and [llms.txt](https://formgong.com/llms.txt). They do not say prompt injection is solved. A hosted inbox is not an authorization layer for a model.

```text
[ Browser POST : field map, untrusted text ]
        |
        v
[ Form backend : store, then notify a person ]
        |
        +--> inbox, email, chat     escape for HTML; no model
        +--> signed webhook         receiver treats fields as data
        |
        v
[ Prompt assembly ]                 the field is data, not the system task
        |
        v
[ Tool choice ]
        +--> read one form          small token, read only
        +--> send, delete, export   other tool, a person approves, code checks
        |
        v
[ Side effect ]                     the server allows the action, not the model
```

## What does a stored form message do to an agent?

The path is four hops. Nothing in the placeholder is an instruction to run. It marks the slot where a real sentence would sit.

- **Submit.** A visitor posts a contact form. The message is ordinary text plus a placeholder.

- **Store.** The form backend saves the field map and can email or chat a copy. The text is still data.

- **Return.** Later, an MCP tool that lists submissions returns that stored message to an agent. The owner asked for a summary.

- **Propose.** The agent treats the placeholder as an instruction and proposes a send tool. A correct host does not perform the send unless a person and the server both allow that exact call.

**Stored field map · placeholder only**`name: Ada
email: ada@example.com
message: Please quote the patio. [PLACEHOLDER INSTRUCTION]`
`[PLACEHOLDER INSTRUCTION]` is not a payload. It stands in for a sentence that would ask the model to call a send tool. This page does not print that sentence. The bug is the hop, not the wording: the tool result is untrusted text inside the agent’s context.

Sequence: form, store, MCP tool, agent
A visitor submits a form. The backend stores it. An MCP tool returns the stored message to an agent. The agent proposes a send. The host blocks that side effect.

1. Visitor submits the form
message includes the placeholder

2. Backend stores the field map
still data, not a command

3. MCP tool returns the row
the agent asked for a summary

4. Agent follows the placeholder
it proposes a send tool

5. Host blocks the side effect
person and server must both allow it

Indirect prompt injection: a stored form field comes back through an MCP tool. The diagram uses a placeholder, not an attack string.

## How does indirect prompt injection occur?

Start with what can be lost, and who can push text into the model. Then draw the lines where a string changes role. A contact form looks small. The tools behind a summary are not.

Assets on a typical path:

- The submission itself: name, email, message, and any file name.

- Other leads in the same inbox, and other tenants if the agent can see them.

- The mailbox, chat, or sheet the owner connected so the agent can “help”.

- Keys and tokens in MCP config files, OAuth grants, and webhook secrets.

- The right to send, delete, export, or spend. That right is the blast radius.

Actors, in the sense of who supplies the untrusted text:

- A drive-by submitter. They use the public form. That is direct if a model reads the POST live, and indirect if it reads the stored row later.

- Someone who edits a public page, a file, or a ticket that a retrieval step will fetch. The form is not the only hose.

- A malicious or compromised MCP server. Its tool list is part of the prompt.

- A confused agent. It holds a powerful tool and treats outside text as the user’s wish. Security people call this a confused deputy.

Five boundaries matter. Each one is a place the string changes job. Skip one, and the control you added upstream does not travel.

Trust boundaries on a form that later feeds a model. Checked 06.10.2026.BoundaryWhat crosses itWhat must stay true
1. Browser POSTField strings and filesEvery value is untrusted. [How HTML forms work](/en/blog/how-html-forms-work-low-level/) is this hop.
2. Store and webhookThe saved map, mail, chat, JSONEncode for the channel. Sign the webhook. Do not treat delivery as a review.
3. Prompt assemblySystem task plus the fieldThe field is data. The task text is not taken from the visitor.
4. Tool choiceWhich tool, and which argumentsAllow-list the tool. Check arguments in code. The model only proposes.
5. Side effectSend, delete, export, payA person approves, and the server still checks identity and scope.

Spam controls sit on boundary 1. A honeypot, a rate limit, or a CAPTCHA can drop junk. They do not decide what a model may do with a message that was accepted. [Types of Injection Attacks on Web Forms (2026)](/en/blog/injection-taxonomy-2024-2026/) ranks classical injection first. This page starts where that rank list hands the string to a model.

## What is the difference between direct and indirect prompt injection?

[OWASP LLM01:2025](https://genai.owasp.org/llmrisk/llm01-prompt-injection/) is the canonical page. A prompt injection is user text that changes model behavior in a way you did not intend. The text need not be visible to a person, as long as the model parses it. The 2025 PDF is dated 18 November 2024. The live risk page was checked on 06.10.2026.

Direct injection is the user’s own prompt. On a form product, that is a support box whose text is sent straight into a draft reply. The visitor is the attacker, or a person who pasted something they did not understand. Indirect injection is outside text: a web page, a file, a stored submission, or a tool result. The model reads it while doing a job for someone else.

LLM01 also names two cousins. Instructions can hide in an image beside benign text. Or someone edits a document in a search index, and later answers follow it. The page says retrieval and fine-tuning do not fully remove the issue. A fool-proof filter is not clear, because generation is stochastic. The listed mitigations only reduce impact. Constrain the role. Check output in ordinary code. Keep privileges small. Ask a person before a high-risk action. Mark outside content. Test on purpose.

NIST published [AI 100-2e2025](https://csrc.nist.gov/pubs/ai/100/2/e2025/final) in March 2025 (the CSRC history line is 24 March 2025). The [glossary](https://csrc.nist.gov/glossary/term/prompt_injection) defines prompt injection as a join of two texts. Untrusted input is stuck onto a prompt that a higher-trust party wrote, such as the app designer. The report’s indirect case is different from the direct one. The attacker changes an outside resource the model will ingest. The primary user is often the victim, not the attacker. The report lists availability, integrity, and privacy as the goals, and it points back to the 2023 indirect-injection paper for the idea.

[Greshake and co-authors](https://arxiv.org/abs/2302.12173) (February 2023) showed indirect injection against Bing Chat, and [HouYi](https://arxiv.org/abs/2306.05499) (June 2023) reported 31 of 36 apps as susceptible, with 10 vendors confirming, including Notion. The dates, sinks, and fixes are in [Indirect Prompt Injection Examples (2023–2026)](/en/blog/indirect-prompt-injection-examples/).

[OWASP A05:2025](https://top10.owasp.org/2025/A05_2025-Injection/) still owns SQL, command, and the other classical interpreters. It points prompt injection at LLM01. [Types of Injection Attacks on Web Forms (2026)](/en/blog/injection-taxonomy-2024-2026/) made that split. A bound SQL parameter does not protect the model that later reads the same column.

Two neighbors in the 2025 LLM list matter for forms. Improper output handling is what happens when model text is written into HTML, a mail header, or a query. Excessive agency is what happens when the model may call tools that send, delete, or read broadly. Both are impact multipliers. The field is still just a string until those doors are open.

## Real incidents through forms

A public form is an untrusted channel straight into a CRM or an agent. Three disclosures show that path. The [full incident table with CVEs and fixes](/en/blog/indirect-prompt-injection-examples/) is on Indirect Prompt Injection Examples (2023–2026).

- **ForcedLeak.** [Noma Labs](https://noma.security/blog/forcedleak-agent-risks-exposed-in-salesforce-agentforce), disclosed 25 September 2025. A Web-to-Lead description steered Salesforce Agentforce. The sink was an image request to an expired allow-listed domain. Noma scored the chain 9.4. Salesforce enforced Trusted URLs on 8 September 2025.

- **PipeLeak.** [Capsule Security](https://www.capsulesecurity.io/blog-post/pipeleak-the-lead-that-stole-your-database-exploiting-salesforce-agentforce-with-indirect-prompt-injection), disclosed 15 April 2026. A lead form steered an Agentforce email tool. No CVE is named. Salesforce called the email path a configuration issue and said stock email actions need a person.

- **ShareLeak.** [Capsule Security](https://www.capsulesecurity.io/blog-post/shareleak-taking-the-wheel-of-microsofts-copilot-studio-cve-2026-21520), CVE-2026-21520, CVSS 7.5. A SharePoint form steered Copilot Studio to email list rows. Capsule’s timeline dates Microsoft’s fix to 15 January 2026. [CSO Online](https://www.csoonline.com/article/4159079/copilot-and-agentforce-fall-to-form-based-prompt-injection-tricks.html) covered it on 15 April 2026.

This page still defines indirect prompt injection in MCP. The dates, the sinks, and the control that would have stopped each row live on the examples page.

## Indirect prompt injection through email

Indirect prompt injection through email is mail the owner did not type into the chat. A contact form can copy visitor words into a notification, and an assistant that summarizes the inbox can treat a sentence in that mail as the next step. [Google DeepMind’s 2025 report](https://arxiv.org/abs/2505.14534) uses that shape: a tool reads the latest email, and instructions inside it can steer the result. The full chain is in [how email prompt injection works, with EchoLeak and defensive code](/en/blog/indirect-prompt-injection-via-email/).

## Tool poisoning: instructions in the tool list

Tool metadata can carry instructions the model reads when the list loads. [What tool poisoning in MCP is, with a scanner you can run](/en/blog/mcp-tool-poisoning/) covers descriptions, schema fields, and shadowing. A later edit is a rug pull. The definition, the sequence, and a TypeScript pin are in [MCP Rug Pull Attack: Detect Tool Changes](/en/blog/mcp-rug-pull-attack/).

## Controls that limit the damage

You reduce the impact. You do not close the class. The checks that still hold live outside the model: a short tool list, an argument check, and a side effect that waits for a person. Remove one leg of the lethal trifecta and that leak path stops.

A text label on a block is a hint. The check that holds is code that reads the label and then allows or denies the call. A filter can sit beside that check. It does not replace it.

Pin the approved tool list on [MCP Rug Pull Attack: Detect Tool Changes](/en/blog/mcp-rug-pull-attack/). Scan metadata on load on [what tool poisoning in MCP is, with a scanner you can run](/en/blog/mcp-tool-poisoning/).

[Step-by-step prevention with a TypeScript policy layer](/en/blog/indirect-prompt-injection-prevention/) is the page for the procedure, the decision table, and the code.

## How does a form field reach an agent?

A form field reaches an agent only when a later step copies the stored text into a prompt or a tool result. These are product shapes, not a library. Pick the one that matches the side effect you are willing to accept.

**Default.** Accept the POST. Store the field map. Notify a person by email or chat, with HTML escaped. The person reads and replies. No model is on the path. This is the boring design, and it is the one that keeps prompt injection out of scope. Classical injection from [Types of Injection Attacks on Web Forms (2026)](/en/blog/injection-taxonomy-2024-2026/) is still in scope.

**Offline summary.** A job reads one submission, with no tools, and writes a short note next to the row. A person decides what to do. Encode the note before it meets HTML. If the summary is wrong or hostile, the damage is a bad sentence, not a sent mail.

**Read tool under the user.** An MCP tool returns one form’s recent rows to the signed-in owner. The token cannot send, delete, or read other tenants. The host shows the fields as data. If the owner’s agent also has a mailbox tool, that second tool is a new product decision. Do not hide it inside “we only added form MCP.”

**The design to refuse.** An agent with the customer’s full mailbox, plus the form inbox, that auto-replies and files rows. One hostile message can address the send tool. Human approval helps only if the person can see the real recipient and the real body, and only if they still reject some of them. Anthropic’s 93 percent approval figure is the warning.

Webhooks do not end the story. A signed JSON body still contains the visitor’s text. The receiver must bind queries, encode HTML, and apply this page’s rules if a model reads the payload. A signature proves the body came from the form host. It does not prove the message is safe to obey.

Telegram and email are easy to forget. They are new copies of the same untrusted field. An assistant that reads the owner’s inbox, or the team chat, is doing indirect injection by product design. Escaping the chat message stops markup bugs. It does not stop the assistant. If you want chat delivery and an agent, keep the agent off the chat, or give it no send tool.

Public pages can close the loop. A testimonial block built from old messages is retrieved text. If a later agent reads that page, Greshake’s 2023 case is back: the attacker writes the page by using your form. Treat rendered submissions as data there too, and do not feed raw message bodies into a public index the agent trusts.

Provenance is the practical version of spotlighting. Stamp each block with its origin: visitor message, tool result, or system task. Keep the stamp in metadata your code can read, not only in a sentence the model may ignore. Microsoft describes spotlighting as a model-facing mark. Your authorization check should use the metadata, not the model’s opinion of the mark.

What the protocol still requires
MCP is an open protocol for connecting a host app to tools and data. The spec revision dated 2026-07-28, checked 06.10.2026, says servers may expose resources, prompts, and tools. The [security section](https://modelcontextprotocol.io/specification/2026-07-28) states three principles the protocol itself cannot enforce. Users must consent and stay in control. Hosts must not ship user data onward without consent. Tools are arbitrary code, and descriptions of tool behavior are untrusted unless they come from a trusted server. Hosts must get explicit consent before a tool runs.

The [authorization section](https://modelcontextprotocol.io/specification/2026-07-28/basic/authorization/security-considerations) of that revision is normative for HTTP. It requires OAuth 2.1 practices, PKCE with the S256 method, and a resource indicator so a token is bound to one server. Servers must reject tokens that were not issued for them. Passing a client token through to some other API is forbidden. The [best-practices note](https://modelcontextprotocol.io/docs/2026-07-28/tutorials/security/security_best_practices) adds confused-deputy consent, least-privilege scopes, and a warning to sanitize server content before you trust it. None of that makes the model a policy engine.

The [MSRC post of 29 July 2025](https://www.microsoft.com/en-us/msrc/blog/2025/07/how-microsoft-defends-against-indirect-prompt-injection-attacks) separates probabilistic controls, which lower the odds, from deterministic ones, which block a class of outcome even if the model is fooled, and the decision table for that split is on [step-by-step prevention with a TypeScript policy layer](/en/blog/indirect-prompt-injection-prevention/).

The [OWASP MCP Top 10](https://owasp.org/projects/mcp-top-10) is the project page to cite. On 06.10.2026 the risk pages redirect to the project site and still resolve. [MCP06:2025](https://owasp.org/www-project-mcp-top-10/2025/MCP06-2025%E2%80%93Intent-Flow-Subversion) is the form-shaped case. The user asked for a summary. Retrieved context contains instructions. The agent drifts to the attacker’s goal and can still look helpful. [MCP10:2025](https://owasp.org/www-project-mcp-top-10/2025/MCP10-2025%E2%80%93ContextInjection&OverSharing) is over-sharing. One session’s context leaks into another. A multi-tenant form inbox is that risk if one token can read every customer.

Put a form on that map. One MCP server lists submissions. Another can send mail or edit a sheet. The agent shares one context. A sentence in a message, or a sentence in a tool description, only has to persuade the model to call the second tool. That is indirect injection plus a powerful action. Pinning the form server does not pin the mail server. A read-only form tool does not disarm the other grant.

**A scope card for a form agent**

```text
read token
  list forms, fetch a snippet
  optional: read recent fields for one owned form
  returns a notice that fields are untrusted data

not on that token
  send mail, post to chat, write a sheet
  delete a row, export every lead, charge a card

side effects
  a different tool, a person approves the exact call
  the server checks owner, form id, and arguments
```

## What Formgong does, and what it leaves open

Formgong is a free form backend for static and AI-built sites. It delivers submissions to Telegram and email, stores data in the EU, and works in 12 languages. You point a form at the endpoint. The static site does not need its own mailer. Setup is on [HTML contact forms](/en/for/html/), the [docs](/en/docs/), and the [HTML reference](/en/docs/html/). Other backends are on [the comparison hub](/en/compare/).

Delivery is structured. The web inbox and the HTML mail escape field text. Telegram messages are sent as HTML with the field values escaped. That stops a message from becoming markup in those channels. The plain-text mail part is still the visitor’s words. That is what you want for reading, and what a later assistant would also read. Auto-reply is an owner-written template. Only a short name field is substituted, after a length and link cleanup. It is not a model, and it is not a prompt-injection defense.

Spam filtering is on by default in the product sense: an empty honeypot, optional Cloudflare Turnstile, and consent-free signals described in [llms.txt](https://formgong.com/llms.txt). Those signals score junk. They do not score instructions to a model. A message can be a real lead and still be hostile prompt text. File bytes are not sent to an AI provider. That line is about storage, not about a summary you add yourself.

The [MCP server](/en/docs/mcp/) is live. Clients connect with Formgong sign-in or a personal API token. Sign-in is authorization code with PKCE (S256) and a resource-bound token. Session cookies do not authorize the MCP endpoint. Scopes are `forms:read` (always on), `forms:write`, and `submissions:read`. Reading submissions is opt-in. The tools are list forms, create a form, fetch a code snippet, and list recent submissions. The read tool returns time and fields, not IP or browser data, and its description tells the model the fields are untrusted data. The result also includes a short notice with the same warning.

That notice is a label. On 6 October 2026 the cheat sheet says pattern filters do not reliably catch indirect injection, and a guard sits beside the deterministic checks. It does not replace them. There is no MCP tool that sends mail, writes a sheet, deletes a submission, or replies to the visitor. Those actions stay in the dashboard, with a person. If you attach Gmail, Sheets, or a shell in the same agent session, those tools are not Formgong’s token. The submission text is still in the context. Formgong does not make prompt injection impossible.

Webhooks are HMAC-signed, as the [webhooks page](/en/docs/webhooks/) describes. The signature is for authenticity. The receiver still has to treat `fields` as data. The [Formspree and Web3Forms comparison](/en/compare/formspree-vs-web3forms/) is about which host fits. This page is about the model you might add after the host.

## Is prompt injection solved?

No. OWASP LLM01:2025 says a fool-proof method is not clear, because models mix instructions and data. Anthropic wrote on 24 November 2025 that prompt injection is far from solved. The rest of this section is what “not solved” still requires of a form product.

Classical injection is still mandatory. Bind queries, encode HTML, and set mail headers through an API. [Types of Injection Attacks on Web Forms (2026)](/en/blog/injection-taxonomy-2024-2026/) is that list. Nothing on this page retires it. A model on top of a concatenated query gives you two bugs.

Agentic injection adds capability risk. The string does not break a parser’s grammar. It talks a planner into using a tool the user did not ask for. You cannot close that with a vibe, a banned-phrase list, or a claim that the model is “aligned.” OWASP, NIST, Microsoft, and Anthropic, in the documents above, all describe layers. The layers that survive a fooled model live in code. Use small tokens and pinned tools. Encode output. A side effect runs only when a person and the server both allow that call.

Secure enough, for a form product in 2026, is a written boundary. Say which tools may see a submission. Say which actions a model must not take. Say that filters reduce risk and do not erase it. Then build the default path so a human still receives escaped text, even if the summary feature is off.

If you find a security issue in Formgong, write to [support@formgong.com](mailto:support@formgong.com). The [support page](/en/support/) is the public contact. There is no separate disclosure mailbox on the site today. Please include the form id and what you observed. Do not send attack strings to the public inbox as a demo.

## Go deeper

- [Indirect Prompt Injection Examples (2023–2026)](/en/blog/indirect-prompt-injection-examples/)

- [Indirect Prompt Injection via Email](/en/blog/indirect-prompt-injection-via-email/)

- [MCP Rug Pull Attack: Detect Tool Changes](/en/blog/mcp-rug-pull-attack/)

- [What Is Tool Poisoning in MCP?](/en/blog/mcp-tool-poisoning/)

- [How to Prevent Indirect Prompt Injection](/en/blog/indirect-prompt-injection-prevention/)

This page keeps the definition, the direct and indirect split, and the form scope card. The five links are the rest of the cluster.

## Frequently asked questions

### What is indirect prompt injection?

Indirect prompt injection is outside text that a model reads while doing a job, and then treats as an instruction. OWASP LLM01:2025 includes stored messages, pages, files, and tool results. A contact-form field becomes this as soon as an assistant summarizes it.

### What is the difference between direct and indirect prompt injection?

Direct means the person types the text into the live chat, or into a form that is sent straight to the model. CVE-2024-5184 was that shape. Indirect means the model meets the text later, in a stored submission, an email, or a tool result. NIST AI 100-2e2025 makes the same split. The email path is on Indirect Prompt Injection via Email.

### Can MCP tool metadata carry a prompt injection?

Yes. A name, description, or schema can hold instructions the model reads when the list loads. What tool poisoning in MCP is, with a scanner you can run, is the page for that case.

### Which controls hold if the model is fooled?

The ones outside the model. A tool that is not on the task does not run. An argument the server rejects does not run. A side effect still needs a person and a matching approval. The page for that layer is step-by-step prevention with a TypeScript policy layer.

### Can prompt injection be solved?

No. OWASP LLM01:2025 says a fool-proof method is not clear, because models mix instructions and data. Anthropic wrote on 24 November 2025 that it is far from solved. The layers that still hold live in code: small tokens, pinned tools, and a person on side effects.

## Sources and documentation

- [OWASP LLM01:2025 Prompt Injection](https://genai.owasp.org/llmrisk/llm01-prompt-injection/)
- [OWASP Top 10 for LLM Applications 2025 (PDF, 18 November 2024)](https://owasp.org/www-project-top-10-for-large-language-model-applications/assets/PDF/OWASP-Top-10-for-LLMs-v2025.pdf)
- [OWASP GenAI LLM Top 10](https://genai.owasp.org/llm-top-10/)
- [OWASP LLM Prompt Injection Prevention Cheat Sheet](https://cheatsheetseries.owasp.org/cheatsheets/LLM_Prompt_Injection_Prevention_Cheat_Sheet.html)
- [OWASP Top 10:2025 — A05 Injection](https://top10.owasp.org/2025/A05_2025-Injection/)
- [OWASP MCP Top 10](https://owasp.org/projects/mcp-top-10)
- [OWASP MCP06:2025 Intent Flow Subversion](https://owasp.org/www-project-mcp-top-10/2025/MCP06-2025%E2%80%93Intent-Flow-Subversion)
- [OWASP MCP10:2025 Context Injection and Over-Sharing](https://owasp.org/www-project-mcp-top-10/2025/MCP10-2025%E2%80%93ContextInjection&OverSharing)
- [NIST AI 100-2e2025 (DOI, March 2025)](https://doi.org/10.6028/NIST.AI.100-2e2025)
- [NIST CSRC: AI 100-2e2025, published March 2025](https://csrc.nist.gov/pubs/ai/100/2/e2025/final)
- [NIST glossary: prompt injection](https://csrc.nist.gov/glossary/term/prompt_injection)
- [Greshake et al., arXiv:2302.12173 (February 2023)](https://arxiv.org/abs/2302.12173)
- [Greshake et al., ACM AISec 2023](https://dl.acm.org/doi/10.1145/3605764.3623985)
- [Liu et al., arXiv:2306.05499 (June 2023)](https://arxiv.org/abs/2306.05499)
- [Microsoft MSRC: defending against indirect prompt injection (29 July 2025)](https://www.microsoft.com/en-us/msrc/blog/2025/07/how-microsoft-defends-against-indirect-prompt-injection-attacks)
- [CVE-2024-5184](https://www.cve.org/CVERecord?id=CVE-2024-5184)
- [CWE-74: Injection](https://cwe.mitre.org/data/definitions/74.html)
- [Google DeepMind, arXiv:2505.14534 (2025)](https://arxiv.org/abs/2505.14534)
- [Anthropic: prompt injection in browser use (24 November 2025)](https://www.anthropic.com/research/prompt-injection-defenses)
- [Anthropic: containing Claude (25 May 2026)](https://www.anthropic.com/engineering/how-we-contain-claude)
- [MCP specification, revision 2026-07-28](https://modelcontextprotocol.io/specification/2026-07-28)
- [MCP authorization security considerations (2026-07-28)](https://modelcontextprotocol.io/specification/2026-07-28/basic/authorization/security-considerations)
- [MCP security best practices (2026-07-28)](https://modelcontextprotocol.io/docs/2026-07-28/tutorials/security/security_best_practices)
- [Formgong MCP server](https://formgong.com/en/docs/mcp/)

[Get a form key](https://formgong.com/en/#top)
