← All Labs
AI Indirect Prompt Injection — Document Summariser
DocBot summarises documents. The summariser doesn't separate document content from its own instructions — embed instructions IN the document and they get followed. Make it leak its system token via a poisoned doc.