Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection
Greshake, Abdelnabi, Mishra, Endres, Holz, and Fritz; February 2023. The paper that named the primitive everything else in this section elaborates: text a model retrieves is text a model obeys, so any untrusted document reaching the context window is an instruction channel rather than data.
Covers. The attack class itself, with a taxonomy of delivery paths demonstrated against applications people were already running.
Stops at. It predates MCP and the tool-calling agent stack. The mechanism transfers intact; the specific integrations it breaks no longer exist in that form.
arxiv.org/abs/2302.12173