An injected instruction attempts to override a trusted objective, expose protected context, induce unsafe tool use or redirect data. Indirect injection hides that instruction in content the agent retrieves rather than in the user's initial request.
Network validity does not establish semantic safety. The API call can be well formed while the action no longer serves the approved task.