Prompt Injection is malicious instructions hidden in user input or retrieved content. It sits in the Incentives dimension (INC) of the Human Behavior Taxonomy™ as element HBT-INC-0222, within the Risk family. The core principle: malicious instructions hidden in user input or retrieved content. In incentive terms, it matters because it changes the payoff people perceive before they choose — which means it can be designed for, or exploited.
Scientific Definition
Malicious instructions hidden in user input or retrieved content.
Plain-English Definition
Malicious instructions hidden in user input or retrieved content.
Feynman Explanation
Your agent's loyalty just got rewritten by a webpage.
Core Principle
Malicious instructions hidden in user input or retrieved content.
Mechanisms
Pending editorial review.
Pending editorial review.
Pending editorial review.
Pending editorial review.
Pending editorial review.
Pending editorial review.
Pending editorial review.
Inputs (Triggers)
Pending editorial review.
Outputs (Behaviors)
Pending editorial review.
Behavioral Signature
Your agent's loyalty just got rewritten by a webpage.
Examples
- Indirect prompt injection through documents an agent reads.
- Major security risk for agent deployments.
Pending editorial review.
Original analysis from The Incentives Lab — how this element behaves inside real payoff structures.
Why this element matters to incentive design
This is one of the elements leaders describe as a values gap. It is a payoff gap. The mechanism underneath it operates in the Incentives dimension — what makes behavior more or less likely?. You can recognize it in the field by its signature: your agent's loyalty just got rewritten by a webpage. Every element in the Incentives dimension changes the perceived payoff of an action before the action happens, which is exactly where incentive design has leverage.
How it gets exploited
Left undesigned, major security risk for agent deployments. It is amplified whenever major security risk for agent deployments. Inside organizations that shows up as major security risk for agent deployments. The pattern is the same one Goodhart's Law describes: the measurable proxy attracts the effort, and the purpose behind it quietly loses funding.
How the Lab designs around it
The redesign move is to treat all input as adversarial. Output validation. Sandboxing. Design against it the way you would design against a known failure mode — assume it will appear, and price the exploit before someone finds it.
Famous Experiments
Pending editorial review.
Design Principles
- Treat all input as adversarial. Output validation. Sandboxing.
Measurement Approaches
Pending editorial review.
Evidence
Pending editorial review.
Pending editorial review.
The Perverse Incentive Lens™
How this behavior is exploited — and how to redesign around it.
- Treat all input as adversarial. Output validation. Sandboxing.
Pending editorial review.
Pending editorial review.
Interactive Mini Network
Click any neighbor to re-center the graph and follow the threads of connection.
Knowledge Graph Neighbors
Auto-linked to the rest of the Human Behavior Taxonomy by family, domain, dimension, and shared keywords.
When the agent acts, who's responsible?
Categorizing AI use cases by risk level.
Systematic skew in model behavior across groups.
Testing model behavior on hypothetical alternate inputs.
Adding noise to data to protect individual privacy.
Quantitative measures of model behavior across groups.
Training models across devices without centralizing data.
Bypassing model safety constraints.
Individual speed gains hide collective quality decline.
Adversarial testing of AI systems.
Foundational skills erode through AI offloading.
Cache common prompt prefixes to reduce cost and latency.
Where Prompt Injection is cited in the corpus
Essays, field guides, and diagnostics from The Incentives Lab that apply this element.
- Field guideIncentives: definition, types, examples
The parent field guide for this element.
- ReferenceThe laws of incentives
Goodhart, Campbell, and the Cobra Effect.
- EssayAI Agents Inherit Your Incentives
How this element propagates into automated systems.
- EssayIncentives Under Crisis
How this element behaves under pressure.
- ReferenceThe Periodic Table of Human Behavior
The full 1,267-element map this page belongs to.
- CourseIncentives 101
The free ten-part primer on reading a payoff structure.
Questions about Prompt Injection
- What is Prompt Injection?
- Prompt Injection is malicious instructions hidden in user input or retrieved content. It sits in the Incentives dimension (INC) of the Human Behavior Taxonomy™ as element HBT-INC-0222, within the Risk family. The core principle: malicious instructions hidden in user input or retrieved content. In incentive terms, it matters because it changes the payoff people perceive before they choose — which means it can be designed for, or exploited.
- What is an example of Prompt Injection?
- Major security risk for agent deployments. The Incentives Lab catalogs everyday, organizational, and historical instances of this element on its Human Behavior Taxonomy™ page (HBT-INC-0222).
- How is Prompt Injection exploited?
- Major security risk for agent deployments.
- How do you design around Prompt Injection?
- Treat all input as adversarial. Output validation. Sandboxing.
- Which behavioral dimension does Prompt Injection belong to?
- Prompt Injection is classified in the Incentives dimension (INC) of the Human Behavior Taxonomy™, family "Risk", class "AI-Behavioral Coupling". Its permanent identifier is HBT-INC-0222 and its evidence grade is C.