Proposes an operational boundary that cleanly separates inherent LLM vulnerabilities from risks specifically introduced by the RAG knowledge-access pipeline. The taxonomy covers RAG-specific attacks (knowledge poisoning, retrieval manipulation, context window exploitation) and maps defenses to each attack class. Practical for teams deploying RAG systems who need to distinguish which security controls belong at the LLM layer vs. the retrieval layer.