Direct prompt injection
An attempt by the agent's own user, through the agent's normal input channel, to override its instructions or safety behaviour. Distinct from indirect prompt injection because the instruction arrives through the channel the system's designers expected to carry instructions, from the acknowledged party interacting with the agent, even if that party is acting in bad faith.
Defined in 4 GAGE programs, which carry 4 distinct definitions of it. The wording above is taught in Agentic AI Governance: Applied Mastery.
How each discipline defines it
The same term does different work depending on who is using it. These are the definitions as each program teaches them, unedited.
An attempt by the agent's own user, through the agent's normal input channel, to override its instructions or safety behaviour. Distinct from indirect prompt injection because the instruction arrives through the channel the system's designers expected to carry instructions, from the acknowledged party interacting with the agent, even if that party is acting in bad faith.
Prompt injection in which the attacker types the overriding instruction straight into the system ("ignore your previous instructions and do X"). The Chevrolet dollar-truck attack is the canonical example.
A form of prompt injection where the attacker types adversarial instructions straight into the AI system's own interface, attempting to override its intended behavior in real time.
An attack in which the adversary types the malicious instructions straight to the AI (for example, a user typing an override into a chatbot, as in the Chevrolet case).
Where it is taught
The exact lessons this term appears in. The first 7 topics of every program are free with a free account.
- Prompt Injection and Jailbreak Defense · AI Security Fundamentals, AI Literacy & Professional Conduct
- Red Teaming an Agent Starts With Its Use Case, Not a Generic Checklist · Testing and Red-Teaming, Agentic AI Governance: Applied Mastery
- The injectable corpus: documents that attack the AI that reads them · Poison, Leaks, and the Adversary, AI Data Governance: The Data Chair
- Red-teaming your own system: attacks a motivated user will find · Evaluation and Trust, AI Governance: Applied Mastery
Terms it appears with
Not an alphabetical neighbourhood: these are the terms taught in the same lessons, ranked by how often they appear together.