Agent Prompt Injection Defense

Hardening patterns and detection techniques for indirect prompt injection (IDPI) and cross-domain prompt injection (XPIA) attacks against AI agents, specifically OpenClaw. Use when designing agent workflows that consume external content, reviewing agent configurations for injection risk, auditing skills/tools that fetch web content, responding to injection incidents, or building defenses into multi-agent pipelines. Covers the PromptArmor link-preview exfiltration technique, ClawJacked WebSocket hijacking, log poisoning injection, malicious ClawHub skills, 22 real-world IDPI payload techniques documented by Palo Alto Unit42, and CNCERT advisory on OpenClaw deployments.

nickgallick 087f135 4 files · 27.6 KB Updated 0 repo stars

File contents

nickgallick/perlantir-fleet/tree/main/workspace-forge/skills/agent-prompt-injection-defense commit 087f135579

Frequently asked questions

npx skillmds add nickgallick/agent-prompt-injection-defense