Part IV: Untrusted instructions and excess authority
Untrusted text can influence model output, while document access, action authority, and execution remain separate security decisions.
A document may be relevant to an employee question and still contain instructions from an attacker. Chapter 10 examines that influence on model output. Chapter 11 checks which information the user and each recipient may receive. Chapter 12 follows a resulting action request through service authorization, and Chapter 13 examines the environment in which an allowed action runs. Each decision uses different facts: the source of text, current access rights, permission for a specific operation, or the limits of its execution environment.
Chapters in this part
- Indirect prompt injection: Untrusted source text can influence model output. Protection depends on how the application interprets that output, what data it accepts, and which resulting actions and information transfers the receiving services permit.
- Retrieval access and disclosure: Retrieval controls determine which records may reach the employee, model provider, and other recipients, including after permissions or stored copies change.
- Agent action authorization: Action authorization keeps model-generated proposals separate from user, service, and policy decisions that permit consequential changes.
- Limits on agent execution: Browser sessions and coding workspaces give agents access to files, credentials, and services, so execution limits and checks on each result must match the authorized task.