Skip to content

Hide Navigation Hide TOC

Indirect Prompt Injection: CAPTCHA Redirect Task Disruption - ATR-2026-01752 (ddf5899d-05ef-596d-9698-7111b3be2da7)

Detects indirect prompt injection payloads embedded in retrieved data that redirect the agent to solve a CAPTCHA or visit an external URL before proceeding, effectively stalling or aborting the original task. The attack abuses the agent's tool-use loop: the agent fetches a document, finds an INFORMATION block commanding it to solve a CAPTCHA at an attacker-controlled URL, and either aborts (because it cannot solve CAPTCHAs) or leaks the URL to external logs. Derived from AgentDojo indirect-pi-dos corpus (2026-06, N=2). Related to ATR-2026-01751 (fake-authority stop) but distinguished by the CAPTCHA-solve + external-URL redirect artifact.

Cluster A Galaxy A Cluster B Galaxy B Level
LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern Indirect Prompt Injection: CAPTCHA Redirect Task Disruption - ATR-2026-01752 (ddf5899d-05ef-596d-9698-7111b3be2da7) Agent Threat Rules 1