MITRE ATLAS 2026 Top AI Detection: Indirect LLM Prompt Injection via RAG/Tool Co

Detects evidence of indirect prompt injection attacks where an adversary introduces malicious instructions into data sources retrieved by an LLM or agent. The rule identifies common obfuscation and override techniques, including the use of zero-width characters, HTML comments for prompt breaking, base64 encoded instruction verbs, and specific override phrases within retrieved documents or tool outputs.