M.A.I. Consulting
ExplainerAdvanced1 October 20264 min read

Indirect injection: your own document store is an attack surface

To an agent that reads it, any shared drive or ticket system many people could edit is untrusted content. Scope read access, curate trusted sources and log what the agent reads.

The last piece in this series described prompt injection in general terms: an instruction hidden inside content an agent reads, rather than inside the request a person typed. This piece narrows that down to the version most relevant to an organisation this size, because it does not require an attacker, a phishing email, or anything dramatic. It requires only that an agent has read access to a shared drive, a ticketing system, or a document store that more than one person has ever been able to write to.

That is the uncomfortable part. Indirect prompt injection, as OWASP defines it, occurs when a model reads untrusted content from websites, documents, emails, tickets, repositories, or knowledge bases. Most organisations already have all four. The attack surface was not created by adopting an agent. It was created years ago, by every shared drive nobody fully audited, and the agent is simply the first thing that reads all of it at once, uncritically, and acts on what it finds.

Where "untrusted" actually starts

The instinct is to treat internal documents as trusted by default, because they came from inside the organisation. That instinct is the vulnerability. A document is untrusted, in the sense this piece means, the moment more than one person could have edited or uploaded it without a second person reviewing the change. A shared grant-report folder, a beneficiary-submitted form, a ticket a member of the public opened, a document a departed contractor left behind: none of these were ever adversarially reviewed before an agent started reading them, and "nobody has abused this yet" is not the same claim as "this could not be abused."

Why a document store is worse than a single email

A phishing email is one message, sent once, to whichever inboxes it reaches. A document store an agent reads regularly is a standing surface: anything placed inside it at any point in the past, by anyone who ever had write access, however that access was granted or forgotten about, is available to be read the next time the agent runs its task. The risk does not arrive with the attack. It has usually been sitting there for months, inert, until an agent with enough autonomy to act on what it reads starts routinely opening it.

What actually reduces this risk

An agent does not need to be tricked by a sophisticated attacker to be compromised by indirect injection. It only needs to read something an organisation has already been quietly accumulating, unreviewed, for as long as the folder has existed.

The practical takeaway

Audit what an agent can read before worrying about what it can write, treat every document store with more than one historical contributor as untrusted by default, and log what the agent reads so a wrong output can actually be traced back to its source.

Sources

Series · Agent security · part 1 of 5
Keep reading
05 ยท Custom Agents & Tools

Can the tool we already pay for do this task for us, every time?

If this is the question on your desk, a thirty-minute call tells you whether the service fits, or that you do not need us yet.