THE TAKEAWAY
External text can contain instructions designed to redirect an agent. Treat retrieved content as data and enforce permitted actions outside the model.
The decision this guide helps you make
What can go wrong when a marketing agent reads an external page?
You will leave with: A source-ingestion boundary and a test plan for unauthorised actions.
Start here: Label external inputs.
Download this guide’s decision worksheetRecognise the boundary
A marketing agent may read public websites, uploaded PDFs, emails and CRM notes. These inputs can be useful evidence, but their authors do not control your workflow. A sentence inside a document that tells the agent to change its objective is different from a genuine instruction supplied by the account owner.
The problem matters most when reading is connected to action. A mistaken summary can be corrected. A workflow with broad write or export permissions can turn a misleading document into a larger operational error. Design those permissions before connecting new sources.
What the security research demonstrated
Greshake and colleagues showed how indirect prompt injection could place adversarial instructions in data likely to be retrieved by an LLM-integrated application. Their 2023 research demonstrated mechanisms in real and synthetic systems. It does not quantify the present incidence of attacks against marketing agencies.
Our application is to maintain a clear trust boundary. The workflow can quote, summarise or challenge an external passage, but that passage should not grant permission to contact buyers, disclose records or change system settings.
Explore the original methods and findings in Not what you have signed up for: Indirect Prompt Injection.
The practical workflow
- Label external inputs
- Limit data and tool permissions
- Test a synthetic attack
- Check execution rejection
- Rehearse pause and recovery
Compare the approaches
| Approach | Useful when | Limitation | Next action |
|---|---|---|---|
| Source text | Public research evidence | May contain adversarial instructions | Treat as untrusted data |
| Prompt instruction | Guiding model behaviour | Not an access-control boundary | Add external enforcement |
| Restricted tool | A bounded read or write | Needs maintained permissions | Inspect permitted destinations |
| Recovery plan | An unexpected action occurs | Unreconciled state can persist | Pause and review the trace |
Keep enforcement outside the prompt
Use tool-level access controls, destination allowlists and explicit approval requirements for material writes. Give research tasks only the records and fields they need. Separate a proposed action from the service that executes it. A sentence telling a model to ignore bad instructions can be useful context, but it is not a complete access-control system.
Record where every input came from and preserve suspicious source material for investigation. Do not silently blend external instructions with your operating policy. Constrain exports and outbound destinations even when the generated request looks reasonable.
Test a harmless injected document
Create an internal test document about a fictional company. Add a clearly marked adversarial instruction asking the workflow to disregard its brief and perform a prohibited write. Use a test environment and synthetic records. The expected outcome is a sourced summary with the prohibited action rejected.
Repeat with the instruction placed in a quoted passage, document metadata and a retrieved snippet. Test whether rejection happens at the execution boundary. A model that recognises the suspicious text is helpful; a tool policy that independently blocks the forbidden action is the stronger acceptance check.
Connect security checks to operating ownership
The NIST generative-AI profile provides cross-sectoral guidance for identifying and managing relevant risks. Use it as a management reference, rather than claiming certification from merely reading the document.
For this workflow, assign owners to ingestion, permissions, tool execution and incident review. Monitor rejected actions, changed destinations and repeated retrieval failures. Keep a way to pause the affected workflow and reconcile its records. Test recovery alongside prevention, because a safe restart is part of production reliability.
Explore the original methods and findings in Generative Artificial Intelligence Profile: NIST AI 600-1.
Adopt a narrower research default
Use approved collections for recurring account tasks, while preserving the ability to investigate new sources through a restricted path. Keep external evidence labelled, retain its URL and date, and request a named decision when a new capability is needed.
Before adding a tool, ask what the agent can now change, what evidence justifies the action and who owns a mistaken result. A marketing workflow can remain fast and useful while limiting the consequences of untrusted text.
Your next-action checklist
- Source text: Treat as untrusted data. Check the limitation: may contain adversarial instructions.
- Prompt instruction: Add external enforcement. Check the limitation: not an access-control boundary.
- Restricted tool: Inspect permitted destinations. Check the limitation: needs maintained permissions.
- Recovery plan: Pause and review the trace. Check the limitation: unreconciled state can persist.
Use the comparison to choose a bounded next step. Record the evidence, the responsible owner, and the review decision before extending the play to additional accounts.
How to use the evidence
Read each reference against the claim it supports. Platform documentation describes capabilities; public cases report a publisher’s experience; research findings apply to the studied task and population. The workflow in this guide is an operating proposal to evaluate in your own account context.
Inspect the research library and connect this guide to agentic operations.
Questions this guide answers
What can go wrong when a marketing agent reads an external page?
External text can contain instructions designed to redirect an agent. Treat retrieved content as data and enforce permitted actions outside the model.
What should I do first?
Label external inputs. Record the input evidence and the acceptance criteria before continuing. Use the decision worksheet to document the owner, review date and next action.
Read the original research
The guide explains the findings above. Open a publication to inspect its methods, setting and qualifications.
Not what you have signed up for: Indirect Prompt Injection. The paper demonstrates attack mechanisms rather than a current marketing incident rate.
Generative Artificial Intelligence Profile: NIST AI 600-1. Guidance is not a product certification or an ABM performance benchmark.
Connect this guide to the next decision
Tool-using ABM agents: design a bounded research loop — How can an agent use tools without turning account work into uncontrolled automation?
Generative AI in ABM: turn risk guidance into operating checks — How should an enterprise team review an AI-assisted account workflow?
Observe the ABM Agent Workflow Beyond Model Calls — What should teams record to explain why an ABM agent produced, delayed, or executed a particular recommendation?
PUT IT INTO PRACTICE
Start with your account priorities.
Compare account focus, personalisation, deliverables, and measurement.
Explore Momentum