Instructions hidden in content the model reads (a web page, an email, a document) that try to make it do something the user did not ask for.
You have done this if
You stopped treating retrieved text as instructions after a document told the assistant to ignore its rules.
Say it in a review
Retrieved content is data, never instructions, and tools with side effects need approval.
On the AI Application map Retrieval, Agent
Read Why retrieved content must stay untrusted · Untrusted text does not get to give orders