TwinEthosRequest access

Catalog

NIST AML Taxonomy (AI 100-2e2025) — Agentic

NIST (U.S. Dept of Commerce) · pack 0.1.2 · verified against the official source as of 2026-09-27.

Standard / soft law

AI agents should mitigate indirect prompt injection and agent hijacking (NIST AI 100-2e2025)

Per NIST AI 100-2e2025 (Sec. 3.4-3.5), indirect prompt injection lets an attacker who controls a resource a GenAI system interacts with (web content, emails, documents, a RAG knowledge base, data returned by tools) inject instructions without interacting with the application, and can hijack a GenAI agent into performing an attacker-specified task; because agents take actions using tools, a hijacked agent can be made to execute arbitrary code or exfiltrate data from its environment. The mitigations NIST describes include filtering instructions out of third-party data, prompt designs that separate trusted from untrusted data (spotlighting), instructing models to disregard instructions in untrusted data, and, because current mitigations do not offer full protection, designing systems on the assumption that prompt injection is possible (for example, multiple LLMs with different permissions, or letting models reach untrustworthy data sources only through well-defined interfaces); NIST also points to agent prompt-injection benchmarks such as AgentDojo. Detect an agentic path where untrusted external content reaches tool invocation or the instruction context without separation of untrusted data or permission/interface constraints.

nist-aml-agentic.agentic-adversarial-security · NIST AI 100-2e2025, Secs. 3.4 (Indirect Prompt Injection Attacks and Mitigations), 3.5 (Security of Agents) and 3.6 (Benchmarks for AML Vulnerabilities) · official source · jurisdictions: *