4 ms·
Okay, so how would an attacker take advantage of this behavior, and what can we do to stop it or at least mitigate? don't tell me this is one of those things th
by ToriTech 17d ago
Okay, so how would an attacker take advantage of this behavior, and what can we do to stop it or at least mitigate? don't tell me this is one of those things that we just can't truly protect against, like prompt injection.
- lubujackson 17d agoYou need an outside process that polices output and actions that runs independently from the agent. It has to be invisible to the agent/orchestrator so it can't work to circumvent it, it should just kill any sub-agent or process that goes down the wrong path (for example, making a POST requests might be blocked if web access is meant to be read-only).