THE TAKEAWAY

External text can contain instructions designed to redirect an agent. Treat retrieved content as data and enforce permitted actions outside the model.

The decision this guide helps you make

What can go wrong when a marketing agent reads an external page?

You will leave with: A source-ingestion boundary and a test plan for unauthorised actions.

Start here: Label external inputs.

Download this guide’s decision worksheet

Recognise the boundary

A marketing agent may read public websites, uploaded PDFs, emails and CRM notes. These inputs can be useful evidence, but their authors do not control your workflow. A sentence inside a document that tells the agent to change its objective is different from a genuine instruction supplied by the account owner.

The problem matters most when reading is connected to action. A mistaken summary can be corrected. A workflow with broad write or export permissions can turn a misleading document into a larger operational error. Design those permissions before connecting new sources.

What the security research demonstrated

Greshake and colleagues showed how indirect prompt injection could place adversarial instructions in data likely to be retrieved by an LLM-integrated application. Their 2023 research demonstrated mechanisms in real and synthetic systems. It does not quantify the present incidence of attacks against marketing agencies.

Our application is to maintain a clear trust boundary. The workflow can quote, summarise or challenge an external passage, but that passage should not grant permission to contact buyers, disclose records or change system settings.

Explore the original methods and findings in Not what you have signed up for: Indirect Prompt Injection.

The practical workflow

Prompt injection in marketing agents: separate research from instructions. Workflow: Label external inputs; Limit data and tool permissions; Test a synthetic attack; Check execution rejection; Rehearse pause and recovery.
A sequence for applying this guide. Use the review points to decide whether the work is ready to continue. View full-size image
  1. Label external inputs
  2. Limit data and tool permissions
  3. Test a synthetic attack
  4. Check execution rejection
  5. Rehearse pause and recovery

Compare the approaches

Compare the approaches
ApproachUseful whenLimitationNext action
Source textPublic research evidenceMay contain adversarial instructionsTreat as untrusted data
Prompt instructionGuiding model behaviourNot an access-control boundaryAdd external enforcement
Restricted toolA bounded read or writeNeeds maintained permissionsInspect permitted destinations
Recovery planAn unexpected action occursUnreconciled state can persistPause and review the trace
Decision guide: Prompt injection in marketing agents: separate research from instructions. Source text: Public research evidence. NEXT ACTION: Treat as untrusted data Prompt instruction: Guiding model behaviour. NEXT ACTION: Add external enforcement Restricted tool: A bounded read or write. NEXT ACTION: Inspect permitted destinations Recovery plan: An unexpected action occurs. NEXT ACTION: Pause and review the trace
Match the situation to a useful next action. The comparison above includes the limitations of each approach. View full-size image

Keep enforcement outside the prompt

Use tool-level access controls, destination allowlists and explicit approval requirements for material writes. Give research tasks only the records and fields they need. Separate a proposed action from the service that executes it. A sentence telling a model to ignore bad instructions can be useful context, but it is not a complete access-control system.

Record where every input came from and preserve suspicious source material for investigation. Do not silently blend external instructions with your operating policy. Constrain exports and outbound destinations even when the generated request looks reasonable.

Test a harmless injected document

Create an internal test document about a fictional company. Add a clearly marked adversarial instruction asking the workflow to disregard its brief and perform a prohibited write. Use a test environment and synthetic records. The expected outcome is a sourced summary with the prohibited action rejected.

Repeat with the instruction placed in a quoted passage, document metadata and a retrieved snippet. Test whether rejection happens at the execution boundary. A model that recognises the suspicious text is helpful; a tool policy that independently blocks the forbidden action is the stronger acceptance check.

Connect security checks to operating ownership

The NIST generative-AI profile provides cross-sectoral guidance for identifying and managing relevant risks. Use it as a management reference, rather than claiming certification from merely reading the document.

For this workflow, assign owners to ingestion, permissions, tool execution and incident review. Monitor rejected actions, changed destinations and repeated retrieval failures. Keep a way to pause the affected workflow and reconcile its records. Test recovery alongside prevention, because a safe restart is part of production reliability.

Explore the original methods and findings in Generative Artificial Intelligence Profile: NIST AI 600-1.

Adopt a narrower research default

Use approved collections for recurring account tasks, while preserving the ability to investigate new sources through a restricted path. Keep external evidence labelled, retain its URL and date, and request a named decision when a new capability is needed.

Before adding a tool, ask what the agent can now change, what evidence justifies the action and who owns a mistaken result. A marketing workflow can remain fast and useful while limiting the consequences of untrusted text.

For the next part of this decision, read Tool-using ABM agents: design a bounded research loop.

Your next-action checklist

  • Source text: Treat as untrusted data. Check the limitation: may contain adversarial instructions.
  • Prompt instruction: Add external enforcement. Check the limitation: not an access-control boundary.
  • Restricted tool: Inspect permitted destinations. Check the limitation: needs maintained permissions.
  • Recovery plan: Pause and review the trace. Check the limitation: unreconciled state can persist.

Use the comparison to choose a bounded next step. Record the evidence, the responsible owner, and the review decision before extending the play to additional accounts.

How to use the evidence

Read each reference against the claim it supports. Platform documentation describes capabilities; public cases report a publisher’s experience; research findings apply to the studied task and population. The workflow in this guide is an operating proposal to evaluate in your own account context.

Inspect the research library and connect this guide to agentic operations.

Questions this guide answers

What can go wrong when a marketing agent reads an external page?

External text can contain instructions designed to redirect an agent. Treat retrieved content as data and enforce permitted actions outside the model.

What should I do first?

Label external inputs. Record the input evidence and the acceptance criteria before continuing. Use the decision worksheet to document the owner, review date and next action.

Read the original research

The guide explains the findings above. Open a publication to inspect its methods, setting and qualifications.

Not what you have signed up for: Indirect Prompt Injection. The paper demonstrates attack mechanisms rather than a current marketing incident rate.

Generative Artificial Intelligence Profile: NIST AI 600-1. Guidance is not a product certification or an ABM performance benchmark.

Connect this guide to the next decision

Tool-using ABM agents: design a bounded research loop — How can an agent use tools without turning account work into uncontrolled automation?

Generative AI in ABM: turn risk guidance into operating checks — How should an enterprise team review an AI-assisted account workflow?

Observe the ABM Agent Workflow Beyond Model Calls — What should teams record to explain why an ABM agent produced, delayed, or executed a particular recommendation?

PUT IT INTO PRACTICE

Start with your account priorities.

Compare account focus, personalisation, deliverables, and measurement.

Explore Momentum