AI Agent Security: Prompt Injection, Tools, and Trust Boundaries

Browse articles on prompt injection, AI agent trust boundaries, tool authorization, request assembly, orchestration risk, and security controls.

Start by problem

Choose the article path by the decision or control you need first.

Core articles

14 published articles

Section resources

Context, reusable contracts, related links, and external baselines for this topic.

About this section About this section

Scope

  • Focus: security properties of LLM-powered agentic applications (orchestration/workflows, routing/selection, policy enforcement, session boundaries & context isolation, tool invocation, write-path enforcement).
  • Output style: engineering-oriented; emphasis on testable claims, explicit system boundaries, and mitigation guidance.
  • Public-safe disclosure: some writeups omit PoC strings and raw evidence artifacts; request private evidence under coordinated disclosure when required.

Non-goals (out of scope for this section)

  • General application security guidance that is not specific to agentic applications and orchestration/control-flow.
  • Model-training security or claims about mechanism-level cognition.
Reusable contracts Reusable contracts

Mapped procedures and policies

External baselines External baselines