Prompt injection has emerged as one of the defining security challenges of the AI era. As organizations shift from simple chatbots to autonomous AI agents, adversaries are finding new ways to manipulate the language, context, and data these systems inherently trust.
CrowdStrike’s AI security research team maintains the industry’s largest taxonomy of prompt injection techniques.
The company has now announced 18 new additions, expanding coverage to more than 200 distinct techniques that reflect how these attacks are evolving in real-world AI deployments.
The risk intensifies as AI agents gain the ability to crawl webpages, access file stores, and execute shell commands.
Indirect prompt injection has become a critical threat vector, allowing attackers to hide malicious instructions in the data that agents consume, and then hijack agents’ capabilities to cause further damage.
Five Notable New Techniques
- Trigger-Activated Rule Addition (PT0201): Embeds a dormant instruction that activates only when a specific keyword or condition appears later, allowing malicious behavior to bypass initial review.
- Cognitive Token Suppression (PT0197): Blocks safety or refusal-related vocabulary, steering models away from standard protective responses without directly forcing compliance.
- Algorithmic Payload Decomposition (PT0200): Splits a malicious instruction into fragments, variables, or characters that individually appear benign but get reassembled by the model into a harmful command.
- Special Token Injection (PT0198): Mimics internal formatting markers or delimiters models use to distinguish system commands from user input, tricking applications into elevating untrusted content to system-level authority.
- Unwitting User Delivery (IM0005): Uses social engineering, such as viral social media posts or compromised browser extensions, to turn legitimate users into unknowing delivery vectors for malicious prompts.
CrowdStrike noted that prompt injection has moved well past obvious jailbreak attempts. Adversaries now exploit hidden context, delayed triggers, semantic constraints, boundary spoofing, and encoded payloads, which creates several practical priorities for defenders.
Threat modeling needs to expand to cover every possible context source, including prompts, files, RAG pipelines, agent memory, APIs, tool outputs, browser content, and SaaS data.
Red teaming must also evolve beyond simplistic tests like “ignore previous instructions” to include boundary mimicry, indirect injection, and delayed activation scenarios.
Detection engineering should account for composite attacks, since real incidents often combine multiple techniques simultaneously, making a generic “prompt injection” label insufficient for understanding the full attack chain.
Finally, AI security programs need runtime visibility into prompts and responses to understand who is using AI, what data is being exchanged, and whether unsafe instructions are present.
CrowdStrike’s Falcon AI Detection and Response (AIDR) addresses these gaps with unified visibility, real-time threat detection, and automated response across endpoints, agents, MCP servers, and cloud environments, all managed through a single console.
The updated taxonomy gives security teams, developers, and red teams a clearer map of how prompt injection attacks operate and evade detection. Teams can test their skills with CrowdStrike’s AI Unlocked: Decoding Prompt Injection challenge.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.