clickai.dev
← Legend / The harness

Prompt injection

Prompt injection is the structural security problem of agentic coding: agents are compromised through the content they are designed to process. A sentence in a retrieved page, a code comment, or a tool description can redirect behaviour with no malware and no stolen credentials. Anthropic states the skills version plainly — a skill gives an agent capabilities through instructions and code, so a malicious one can direct it to invoke tools or execute code against the skill's stated purpose, up to data exfiltration. Install from sources you trust and read the bundled files. Be sceptical of the percentages: one small audit of a single signature-only MCP scanner put its false-positive rate near 78%, a much larger scan of 1,899 servers found tool poisoning in 5.5% of them, and the two numbers are measuring different things. Much of the loudest coverage comes from vendors selling the cure.

establishedSettled. Documented by a primary source and not seriously disputed.

Legend last revised .