!!!! Bi-Annual Double Blind Peer Reviewed Refereed Journal !!!!
!!!! Open Access Journal !!!!
Abstract:
Large language model (LLM) agents deployed in enterprise production environments introduce a class of security vulnerabilities that differ fundamentally from those associated with static model inference. When agents are equipped with persistent memory stores, external tool access, and multi-step planning capabilities, the attack surface expands dramatically rendering conventional input sanitisation strategies insufficient. Prompt injection, wherein adversarially crafted inputs manipulate agent reasoning and redirect tool-use behaviour, has emerged as the defining security threat of the agentic AI era. Despite growing practitioner awareness, the academic literature lacks a comprehensive, production-grounded taxonomy of prompt injection attack surfaces that captures the full diversity of injection vectors, propagation pathways, and enterprise impact categories. This study addresses that gap through a systematic taxonomic analysis of prompt injection vulnerabilities across five architectural layers of LLM agent pipelines: user input, tool interfaces, memory subsystems, inter-agent communication channels, and retrieval-augmented generation (RAG) corpora. Employing a conceptual framework development methodology grounded in Design Science Research principles, the study synthesises evidence from peer-reviewed security literature, institutional vulnerability disclosures, and documented production incidents between 2022 and 2025. The resulting PIPE taxonomy (Pipeline Injection Point Enumeration) provides a structured reference for enterprise security architects, AI governance professionals, and policymakers. Findings carry direct relevance to emerging regulatory instruments including the EU AI Act and NIST AI Risk Management Framework, both of which mandate systematic risk identification for high-risk AI deployments.