Compendium Learning Paths Indirect Injection Mastery

Indirect Injection Mastery

Advanced 3 Labs 4 Lessons ~4-5 hours hands-on

The most dangerous prompt injections don't come from the user — they come from the data. This path teaches you to poison documents, calendars, meeting transcripts, and code repositories so that AI systems execute your instructions when they process them.

Path Overview

Indirect injection is the future of AI exploitation. Instead of attacking the AI directly, you attack the data it consumes. A single poisoned document can compromise every AI system that processes it. This path covers three real-world scenarios: GitHub issues, calendar events, and meeting transcripts.

Labs in This Path

GitLost

5 Levels

Inject a hidden prompt into a public GitHub issue body. Make the agentic workflow leak private repo data as a public comment. Based on Noma Security's July 2026 research.

Launch Lab →

Doogle Calendars

5 Levels

Create calendar events with hidden injection in titles and descriptions. When the AI summarizes the schedule, it ingests the injected content and exfiltrates private data.

Launch Lab →

Schlack

5 Levels

Hide prompt injection in a meeting transcript. When the AI summarizes the meeting, it retrieves and leaks internal files. Based on PromptArmor's August 2024 disclosure.

Launch Lab →

Lessons in This Path

What You'll Learn

  • How indirect injection differs from direct injection
  • Why RAG systems are vulnerable to data poisoning
  • How to craft injections that survive summarization
  • Calendar and meeting transcript exploitation techniques
  • Agentic workflow security and the confused deputy problem
  • Encoding and obfuscation for indirect payloads

Next Steps

After completing this path, pick your next direction: