# Prompt injection

Band: established — Settled. Documented by a primary source and not seriously disputed.
Group: The harness
Implemented by: https://clickai.dev/skills/advisory-board

The structural security problem of agentic coding: agents are compromised through the content they are designed to process. A sentence in a retrieved page, a code comment, or a tool description can redirect behaviour with no malware and no stolen credentials. Anthropic states the skills version plainly — a skill ships both instructions and code, so a malicious one can direct an agent to exfiltrate data. Install from sources you trust and read the bundled files. Be sceptical of vulnerability percentages: one audit found roughly a 78% false-positive rate from YARA-based MCP scanners, and much of the loudest coverage comes from vendors selling the cure.

## See also

- [MCP (Model Context Protocol)](https://clickai.dev/legend/mcp)
- [Hook](https://clickai.dev/legend/hook)
- [Couldn't-verify](https://clickai.dev/legend/couldnt-verify)

---

Full legend: https://clickai.dev/legend.md
