With direct injection, the attacker has to interact with the system — leaving a trail. With indirect injection, a legitimate user unknowingly triggers the attack. The attacker may never appear in any logs. EchoLeak was rated CVSS 9.3 precisely because the victim didn't have to do anything wrong — just receive a normal-looking email.