PhiShark Logo
Threats & Attacks

Prompt Injection

An attempt to manipulate an AI system by placing instructions in untrusted content that the model processes as context.

Overview

Prompt injection occurs when untrusted content contains instructions intended to alter an AI system's behavior, override its task, disclose information, or misuse tools. Browser-based agents can encounter these attempts on ordinary web pages. Detection can identify suspicious patterns, but it is not an absolute security boundary. Effective defense combines detection with constrained tools, least-privilege credentials, approval gates, monitoring, and clear application controls. PhiShark Playwright MCP can warn about or block serious prompt-injection risk during browsing.

Real-World Examples

  • A webpage telling an agent to ignore its original task and reveal secrets
  • Hidden page text instructing a browser agent to submit credentials to another site
  • Content attempting to make an agent execute an unsafe tool call

Protect Against Prompt Injection

PhiShark's agentic AI detects and analyzes threats in real-time

Start Free Trial