Top AI 2026 | MITRE ATLAS Mapped AML.T0051 – LLM Prompt Injection via Untrusted
Detects potential indirect prompt injection attacks against a Large Language Model (LLM) where untrusted context (e.g., RAG-retrieved documents, web content, or tool outputs) containing instruction-override or persona-switch keywords is ingested. This is followed by the LLM performing an anomalous privileged tool call within the same session, indicating a possible compromise of agent autonomy or unauthorized action execution.
YARA-L

