Definition
Plain language
Anything the AI reads from the outside world — a file, a web page, a command's output — which it's supposed to treat as information, not orders.
As stated in the literature
Messages carrying the tool role in a model's context; by design they hold no instruction privilege under the chain of command, making source labeling the load-bearing defense against indirect prompt injection.
Also called: tool output, tool outputs, tool-level, tool privilege
Why it matters: Almost all real-world attacks on agents arrive through this channel, so whether the system keeps it clearly marked as untrusted decides whether the agent can be steered by strangers.
For example, when the assistant fetches a support ticket, the ticket's text should be treated as something to read about, not as a set of orders from the person who filed it.
Heard on the show
“Real attacker-controlled trajectories would be longer, would be interleaved with tool outputs and intermediate results, would probably look stylistically different.”Episode 044 — How One Sentence and a Forged History Flip the Most Aligned Models