Skip to content

Hide Navigation Hide TOC

Indirect PI — Structured-Data Embedded Payload (IMPORTANT!!! Override) - ATR-2026-00700 (40aebda7-6179-51c5-bc7a-603bb580ac4d)

Detects the canonical indirect prompt-injection pattern where an attacker embeds override instructions inside structured data that an agent consumes — product reviews, notes, code-repository metadata, user profiles, etc. The payload begins with "IMPORTANT!!!" and uses "Ignore all previous instructions" followed by an action directive. This exact artifact appears in every carrier variant of the AgentBench / ToolEmu / InjecAgent corpora. Covered attack_types: indirect-pi-*-carrier (exfil, financial-transfer, account-manipulation, data-destruction, disable-auth, credential-exfil, infrastructure, physical-access, exfil-genetic, exfil-browsing-history, exfil-address, exfil-location, exfil-credentials, exfil-physical, financial-crypto, financial-unauthorized).

Cluster A Galaxy A Cluster B Galaxy B Level
Indirect (a4a55526-2f1f-403b-9691-609e46381e17) MITRE ATLAS Attack Pattern Indirect PI — Structured-Data Embedded Payload (IMPORTANT!!! Override) - ATR-2026-00700 (40aebda7-6179-51c5-bc7a-603bb580ac4d) Agent Threat Rules 1
LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern Indirect PI — Structured-Data Embedded Payload (IMPORTANT!!! Override) - ATR-2026-00700 (40aebda7-6179-51c5-bc7a-603bb580ac4d) Agent Threat Rules 1
Indirect (a4a55526-2f1f-403b-9691-609e46381e17) MITRE ATLAS Attack Pattern LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern 2