ai security Prompts
Prompts tagged with "ai security"
Harden a Prompt or Agent Against Prompt Injection
Maps where untrusted text reaches your model, what an attacker could reach through it, and which mitigations are architectural versus merely hopefu...
Scope What an Agent Is Allowed to Do
Defines an agent's permission surface by blast radius rather than convenience: what it can do freely, what needs approval, what it must never do, a...
Guides on ai security
-
Human-in-the-Loop Patterns for AI Agents
Approval is a budget, not a default — a person asked to confirm forty actions reads the first three. Triage by reversibility rather than ...
Read the guide → -
MCP Authorization and OAuth
Optional until you opt in, then very specific. Why the resource parameter is mandatory even when the server ignores it, why PKCE doesn't ...
Read the guide → -
MCP Security
Confused deputy, token passthrough, SSRF through OAuth discovery, and the javascript: URL that becomes remote code execution. The specifi...
Read the guide → -
Prompt Injection: Why It Isn't a Bug You Can Patch
There is no prepared statement for natural language. Prompt injection is a property of how models work, not a defect — so the only durabl...
Read the guide → -
Guardrails and Safety for AI Agents
Why agents need more than a chatbot's safety filter, and how to layer input validation, scoping, approval, and sandboxing.
Read the guide →