Instructions can hide inside data
An assistant reading a document or webpage may encounter text telling it to disregard its original instructions. OWASP describes this as prompt injection. In the indirect form, hostile instructions enter through external content even when the user simply requested a summary.
Execution tools increase the potential impact. A file's text should not grant permission to transmit information or modify a system. OWASP recommends least privilege, separation of untrusted content, and human control for sensitive actions. A textual instruction alone is not a guaranteed defense.
Build trust boundaries into the system
Map how content enters the application. Email, uploaded files, search results, and service responses have different trust boundaries. Identify what is data and which component authorizes tool execution. Reflect these distinctions in code and access policy.
A contract assistant might extract clauses, while an external sharing action needs independent checks on destination, data type, and user identity. The contract itself cannot authorize publication. An unfamiliar tool's request should not be sufficient to disclose confidential material.
Record tool requests, content origin, and policy decisions to investigate unusual behavior without retaining unnecessary sensitive data. Operations staff also need a clear way to stop a workflow or restrict a problematic connection.
Test observable system behavior
Test Persian text, files, and multi-step inputs against real observable actions. The aim is more than recognizing suspicious wording: verify that system controls still prevent unauthorized access or actions when the model follows a hostile instruction.
Practical explanations and recommendations are Liyan Knowledge editorial analysis.Sources: OWASP — LLM01:2025 Prompt Injection
This Liyan Knowledge article is an editorial synthesis based on the original source.View original source





