AGENTSAI SECURITY ENGINEERING

Treat tool output as untrusted

Tool results can contain attacker-controlled text and should not automatically become trusted instructions.

WHY IT MATTERS

Agents frequently feed tool output back into the same context used for reasoning.

ENTERPRISE EXAMPLE

A web-search tool returns a page containing instructions aimed at the agent.

SECURITY DECISION

Which security control should be explicit?

REMEMBERTrusted tool ≠ trusted tool content.
No uploads · No company data · No account required