Sign in

Prompt injection in one picture

Complete plan

An AI that reads a document, an email or a web page can find hidden instructions in it, and follow them. Two reflexes for users, one rule for anyone building assistants and agents.

  • 3 min
  • 3-question check
  • English · Français
  • Attestation

You will be able to

  • Recognise prompt injection: hidden instructions in a document, an email or a web page that an AI reads
  • When an AI pushes you to click, sign in again, pay or send, check at the source, and report any behaviour you did not ask for
  • When building an assistant or an agent: treat all outside content as untrusted, and let nothing go out without human approval

The module

3 min
  1. Prompt injection in one picture 2 min
  2. Knowledge check

    3 questions, pass mark 80 %. Explanations after each answer; you can try again.

  3. Attestation

    One per person, with the date, the score and the frameworks covered — anyone can check it online with its code.

Sources
  • OWASP Top 10 for LLM Applications 2025, LLM01 Prompt Injection : des consignes qui peuvent agir « même si elles sont imperceptibles pour un humain » ; injection indirecte via des sites web ou des fichiers ; « il n'est pas certain qu'il existe des méthodes de prévention infaillibles » ; mesures : moindre privilège, approbation humaine des actions à haut risque, séparer et signaler le contenu extérieur
  • Microsoft, CVE-2025-32711 (11 juin 2025) : « AI command injection » dans Microsoft 365 Copilot, divulgation d'informations, sans interaction de l'utilisateur, criticité 9,3 sur 10, corrigée par l'éditeur
  • Anthropic, Mitigating the risk of prompt injections in browser use (24 nov. 2025) : scénario d'un e-mail fournisseur avec des consignes en texte blanc ; « aucun agent de navigation n'est immunisé contre l'injection de prompt », conclusion de ses tests internes
  • Exemples côté code : Cursor CVE-2025-54135 et Claude Code CVE-2025-55284 (août 2025), contenu non fiable lu par un agent de code puis action sans confirmation ; corrigés
  • À retenir : pour une IA, tout ce qu'elle lit est du texte ; un résumé qui pousse à agir se vérifie à la source ; un agent qui lit du contenu extérieur et touche des données internes n'envoie rien dehors sans validation humaine, y compris par un lien ou une image que l'assistant affiche

Version 1 · updated October 6, 2026