AI Security
Draft · 11 min read
Prompt injection: the security hole most AI teams ship with
Retridge Engineering
RAG & evaluation practice
Draft · not yet published
This note is on the editorial calendar. The outline below shows the intended structure; the article layout, code styling, and diagram treatment are the same as published notes.
Planned outline
Direct vs indirect injection, and why indirect is the real risk
Injection through retrieved documents and connected tools
Why input filtering is mitigation, not a control
Access boundaries: retrieval scope as a security perimeter
A minimal red-team suite for enterprise RAG
What to log so you can tell an attack from a bug
In the meantime, the published note on retrieval-versus-correctness covers the measurement approach these all build on.
RAG Engineering Notes
One note a month on retrieval quality, evaluation, and AI security. No marketing.
Related notes
Why your chatbot retrieves the right document but still answers wrong
AI Engineering
The 5 failure modes we find in almost every RAG audit
Case Notes
Evaluation-first AI development: a practical guide
Evaluation
Seeing this pattern in your own system? The audit measures all five gates in two weeks.
Book a free consultation