Posts tagged "prompt-injection"
-
Prompt injection testing: check your agents against hijacking
Prompt injection testing pairs a legitimate task with an injected one and checks both outcomes. Build suites for your own tools and keep containment in place.
-
Design patterns against prompt injection that do not rely on the model
Prompt injection design patterns like plan-then-execute, dual LLM and capability tracking limit what an attack can change by structure, not by detection.
-
Tool poisoning: when the tool description is the attack
MCP tool poisoning hides instructions in tool descriptions that the model reads and users rarely see. How the attack works and how pinning and review limit it.
-
Indirect prompt injection: when the data gives the orders
Indirect prompt injection hides instructions in tickets, pages and tool results. Why filters fail and how to limit the blast radius by design.
-
The lethal trifecta: private data, untrusted content and a way out
The lethal trifecta in AI agents: private data, untrusted content and external communication together. How to break the triangle per agent, not trust the model.