AI Risk Atlas Prototype/DemoUnofficial independent experiment. Not an official xAI product. Scores can be wrong.

Back to watch register
15Prompt injectionBelow the top 20

Indirect injection via retrieved corpora

CapabilityDomain knowledgeAffordanceImpact domainCap-adjacent

Statement (NASA form)

Given that enterprise RAG systems retrieve mail, wikis, and tickets into the prompt, there is a possibility of a planted document steering every later answer that retrieves it resulting in a poisoned wiki page becoming standing instructions.

Likelihood
4Likely
Consequence
3Major
Urgency
3Priority

The attacker does not need your prompt. They need your sharepoint.

Composite 15 = 4×3 + 3

Applicable mitigations

Related on the map