To an agent that reads it, any shared drive or ticket system many people could edit is untrusted content. Scope read access, curate trusted sources and log what the agent reads.
The last piece in this series described prompt injection in general terms: an instruction hidden inside content an agent reads, rather than inside the request a person typed. This piece narrows that down to the version most relevant to an organisation this size, because it does not require an attacker, a phishing email, or anything dramatic. It requires only that an agent has read access to a shared drive, a ticketing system, or a document store that more than one person has ever been able to write to.
That is the uncomfortable part. Indirect prompt injection, as OWASP defines it, occurs when a model reads untrusted content from websites, documents, emails, tickets, repositories, or knowledge bases. Most organisations already have all four. The attack surface was not created by adopting an agent. It was created years ago, by every shared drive nobody fully audited, and the agent is simply the first thing that reads all of it at once, uncritically, and acts on what it finds.
The instinct is to treat internal documents as trusted by default, because they came from inside the organisation. That instinct is the vulnerability. A document is untrusted, in the sense this piece means, the moment more than one person could have edited or uploaded it without a second person reviewing the change. A shared grant-report folder, a beneficiary-submitted form, a ticket a member of the public opened, a document a departed contractor left behind: none of these were ever adversarially reviewed before an agent started reading them, and "nobody has abused this yet" is not the same claim as "this could not be abused."
A phishing email is one message, sent once, to whichever inboxes it reaches. A document store an agent reads regularly is a standing surface: anything placed inside it at any point in the past, by anyone who ever had write access, however that access was granted or forgotten about, is available to be read the next time the agent runs its task. The risk does not arrive with the attack. It has usually been sitting there for months, inert, until an agent with enough autonomy to act on what it reads starts routinely opening it.
An agent does not need to be tricked by a sophisticated attacker to be compromised by indirect injection. It only needs to read something an organisation has already been quietly accumulating, unreviewed, for as long as the folder has existed.
Audit what an agent can read before worrying about what it can write, treat every document store with more than one historical contributor as untrusted by default, and log what the agent reads so a wrong output can actually be traced back to its source.
Prompt injection hides instructions in content an agent reads, and OWASP ranks it the top LLM risk. A plain-language explanation, a vendor's own test figures, and layered defences any organisation can apply.
Custom Agents & Tools · 4 minGuide · 1 October 2026An agent only its builder understands is a personal project running in production. A named owner, a written operating guide and a periodic test set are the minimum bar before calling it finished.
Custom Agents & Tools · 4 minBriefing · 30 September 2026A short, absolute list of tasks no agent should be configured to do: safeguarding referrals, eligibility decisions, payment authorisation and public statements on live matters, where the human is the safeguard.
Custom Agents & Tools · 3 minIf this is the question on your desk, a thirty-minute call tells you whether the service fits, or that you do not need us yet.