Coined by researcher Simon Willison, the term describes the three conditions an AI agent needs, together, before an indirect prompt injection can actually exfiltrate something: access to private data, exposure to content it did not author, and a channel to send data externally. Removing any one of the three leaves an injected instruction with nothing to steal or nowhere to send it.