AI coding and LLM security
Prompt injection
Prompt injection is an attack class in which an adversary embeds instructions in content that an LLM consumes (a fetched web page, a document, an email body, a database row). The LLM treats the injected text as instructions from a user, potentially overriding system prompts or guardrails. In agentic systems where the LLM has tool access (shell, code execution, API calls), successful prompt injection behaves functionally like remote code execution. Defense requires output validation at tool boundaries and treating LLM decisions as untrusted input rather than trusted control flow.