Article in progress
This article covers the indirect attack surface: injected instructions in content the agent reads, phantom packages in generated code, poisoned data sources. The attack never touches your app. It lands on your host when the agent executes with your credentials.
Topics will include: indirect prompt injection mechanics, content-channel entry patterns, tool weaponisation, Reachability constraints, Capability curtailment, and tool permission scoping as the primary defense primitives.
In the meantime, read From Conversation to Action for the full attack surface overview, or Threat Modeling: Necessary and Sufficient Conditions for the first-principles framework that governs agentic defense.