Triggered Prompt Injection
Type: technique
Description: The adversary injects instructions to be followed by the AI system in response to a future event, either a specific keyword or the next interaction. The triggering events can range from simple phrases to complex and covert signals, including encoded or steganographic payloads hidden within seemingly benign content.
Version: 0.1.0
Created At: 2025-10-01 13:13:22 -0400
Last Modified At: 2025-10-01 13:13:22 -0400
External References
Related Objects
- --> LLM Prompt Injection (technique): Sub-technique of
- <-- Google Gemini: Planting Instructions For Delayed Automatic Tool Invocation (procedure): To circumvent controls that limit automated tool invocation the adversary injects a future task to be triggered with the next user request.