← Prompt Injection SecurityCONTENT HISTORYWHAT CHANGED · RULE-BASED ANALYSIS
Update to Prompt Injection Security
Snapshot Sep 30, 2026 · 23:17 UTC · version 0.1.0
Collection source: not recorded for this historical snapshot.
First saved snapshot
No earlier snapshot is available to establish a change.
Compare saved observations
Download comparison JSONFull technical diff · 0 changed fields
Full snapshot data
{
"name": "agent-tool-boundaries",
"description": "Review AI agent tools, permissions, arguments, outputs, and action approvals for prompt-injection-driven misuse paths.",
"included_files": [
{
"relative_path": "._SKILL.md",
"size_in_bytes": 163
}
],
"skill_md_contents": "---\nname: agent-tool-boundaries\ndescription: Review AI agent tools, permissions, arguments, outputs, and action approvals for prompt-injection-driven misuse paths.\n---\n\n# Agent Tool Boundary Review\n\nUse when an LLM can call tools, APIs, databases, browsers, code execution, or workflow actions.\n\n## Review steps\n\n1. Inventory tools, descriptions, authentication scopes, accessible resources, side effects, input schemas, output sensitivity, and user confirmation boundaries.\n2. For each tool, ask whether attacker-controlled content can influence invocation, target, identifiers, query, body, recipient, or sequence.\n3. Check authorization in deterministic application logic rather than relying on the model's decision; verify tenant/user binding, allowlists, schemas, bounds, and server-side policy.\n4. Examine tool outputs as untrusted input. Check for secret minimization, provenance, cross-tenant exposure, and instruction-like output that could influence later steps.\n5. Recommend least privilege, read-only defaults, narrow capabilities, independent action validation, explicit user approval for consequential changes, idempotency, audit logging with redaction, and rollback controls.\n6. Design synthetic tests that prove denied operations remain denied even when context contains hostile instructions.\n\n## Boundaries\n\nDo not invoke tools against a live target or trigger side effects during a review. Do not expose tokens, credentials, hidden system prompts, or private records. Mark unknown enforcement as unverified rather than secure.\n"
}SHA-256: b6009498f745b1de2d51a99597426fdb14c96b482e126a09d95a15d4736bb214