Research

Watch · narrated whiteboard episodesL2

Indirect Prompt Injection via Retrieved Content

A threat-lab breakdown of how untrusted retrieved content hijacks an agent: the attack tree from poisoned source to tool call to exfiltration, each node paired with its concrete hardening - grounded in OWASP LLM Top 10, MITRE ATLAS, and NIST.

Murali Chillakuru·3 episodes
  1. 16 min Episode 1Indirect Prompt Injection: Attack Tree & HardeningA whiteboard walkthrough of how untrusted retrieved content hijacks an agent, modeled as an attack tree with a paired defense for every link.
  2. 13 min Episode 2RAG Poisoning PrimitivesA whiteboard walkthrough of how attackers write into a retrieval corpus, win the ranker, and persist — four primitives, each with an owner and a control.
  3. 13 min Episode 3Tool Abuse & the Confused DeputyA whiteboard walkthrough of how a fooled agent acts with its own authority — the tool-abuse chain, contained with least privilege and per-action mediation.