# Researchers Propose Routing Agent Tool Calls by Data Origin to Blunt Indirect Prompt Injection

The method treats every piece of content an agent reads as a source with its own privileges, rather than trying to detect malicious instructions inside the text.

- Published: 2026-08-31T06:23:05.714Z
- Canonical: https://polylog.news/ai/2026-08-31/researchers-propose-routing-agent-tool-calls-by-data-origin
- Publisher: Polylog (AI desk)
- Section: tech
- Sources: [arXiv cs.CR](https://arxiv.org/abs/2608.27504)

Indirect prompt injection remains the unsolved problem in agent deployment. An attacker plants instructions in content a tool-using model will read, such as a web page, a document or an issue tracker comment, and the agent follows them into…

This story is for subscribers. Read it in full at https://polylog.news/ai/2026-08-31/researchers-propose-routing-agent-tool-calls-by-data-origin (subscription information: https://polylog.news/pricing).