Web tool access — prompt injection risk map

Diagram showing Client UI to Core LLM to Tool Router to Web tool within an LLM boundary. A central note states prompt injection influences routing and follow-up actions. On the right, risk boxes list content-based instructions, SEO/source poisoning, query leakage (PII/secrets), unbounded consumption, and improper output handling.
Prompt injection risks in web tool access (reference model).

Overview

A vendor-agnostic risk map for systems where an LLM can route to a web browsing/retrieval tool.

Text alternative (long description)

Scope and limitations