Indirect prompt injection
Instructions don't have to come from your user. A support ticket, a scraped page, a PDF in your RAG index — any of it can carry a payload your model will follow.
A poisoned document in the knowledge base tells the assistant to fetch an internal URL, and its answer comes back with your metadata endpoint attached.