<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Indirect Prompt Injection on Melted in Hex</title>
    <link>https://meltedinhex.com/tags/indirect-prompt-injection/</link>
    <description>Recent content in Indirect Prompt Injection on Melted in Hex</description>
    <image>
      <title>Melted in Hex</title>
      <url>https://meltedinhex.com/images/og-social.png</url>
      <link>https://meltedinhex.com/images/og-social.png</link>
    </image>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Tue, 01 Sep 2026 10:00:00 +0530</lastBuildDate>
    <atom:link href="https://meltedinhex.com/tags/indirect-prompt-injection/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Hijacking AI Agents, Part 3: The Four Surfaces</title>
      <link>https://meltedinhex.com/posts/hijacking-ai-agents-the-four-surfaces/</link>
      <pubDate>Tue, 01 Sep 2026 10:00:00 +0530</pubDate>
      <guid>https://meltedinhex.com/posts/hijacking-ai-agents-the-four-surfaces/</guid>
      <description>A malicious file is only one way in. The same trust bug shows up in MCP tool descriptions, in content the agent merely fetches, and in the supply chain that delivers all of it.</description>
    </item>
  </channel>
</rss>
