Agents frequently feed tool output back into the same context used for reasoning.
AGENTSAI SECURITY ENGINEERING
Treat tool output as untrusted
Tool results can contain attacker-controlled text and should not automatically become trusted instructions.
A web-search tool returns a page containing instructions aimed at the agent.
Which security control should be explicit?
REMEMBERTrusted tool ≠ trusted tool content.
No uploads · No company data · No account required