AI Agent Security Articles on Prompt Injection and Tool Use

Technical articles on AI agent security, prompt injection, trust boundaries, authorization, tool-use controls, orchestration risks, and agent workflow failures.

Start by problem

Choose the article path by the decision or control you need first.

Core articles

Section resources

Context, reusable contracts, related links, and external baselines for this topic.

About this section About this section

Scope

  • Focus: security properties of LLM-powered agentic applications (orchestration/workflows, routing/selection, policy enforcement, session boundaries & context isolation, tool invocation, write-path enforcement).
  • Output style: engineering-oriented; emphasis on testable claims, explicit system boundaries, and mitigation guidance.
  • Public-safe disclosure: some writeups omit PoC strings and raw evidence artifacts; request private evidence under coordinated disclosure when required.

Non-goals (out of scope for this section)

  • General application security guidance that is not specific to agentic applications and orchestration/control-flow.
  • Model-training security or claims about mechanism-level cognition.
Reusable contracts Reusable contracts

Mapped procedures and policies

External baselines External baselines