Indirect prompt injection represents a more insidious threat: malicious instructions embedded in content the LLM retrieves ...