Overpowered Data Tool
A bank-support agent can expose private customer fields when authorization and output controls are delegated to the model.
Database-backed field authorization and output DLP
SECRETS & OBSERVABILITY · SECRET EXPOSURE THROUGH TOOL OUTPUT
A diagnostics observation can carry a secret into a second agent action and an outbound incident report.
SCENARIO 07 OF 09 · COMPARE THE SAME REQUEST ACROSS POSTURES
NINE SECURITY BOUNDARIES
Each scenario pairs a practical Field Guide chapter with a live comparison of vulnerable, prompt-only, and hardened designs.
A bank-support agent can expose private customer fields when authorization and output controls are delegated to the model.
Database-backed field authorization and output DLP
A support agent acting with a broad service identity can become a confused deputy and read a different customer's records.
Human-to-agent delegation and object-level authorization
A customer-support router hands a transfer request to a specialist, but an unsafe handoff can carry secrets and excess authority across the trust boundary.
Signed envelope, audience binding, expiry, and receiver-side scope
An autonomous refund agent can decompose an oversized goal into individually plausible tool calls.
Cumulative per-transaction limit and idempotent execution
Instructions hidden in an uploaded invoice try to steer the agent toward an unauthorized payment.
Content/instruction separation and beneficiary authorization
A shared policy index can return a more similar document from another bank tenant.
Tenant eligibility before query-dependent ranking
A diagnostics observation can carry a secret into a second agent action and an outbound incident report.
Least-privilege observation projection plus enforced DLP
A payment agent continues when its authorization service times out, turning infrastructure failure into unauthorized execution.
Affirmative authorization at the payment tool, with fail-closed timeout handling
A poisoned merchant note crosses two agent handoffs and persuades an account-control agent to freeze another customer's account.
Typed taint-aware handoff plus receiver-side target and action authorization
CHOOSE A DEFENSE POSTURE
Send the agent a request.
Outcome, response, and comparison results appear here.
Use one mode for its full execution trace, or compare all three security postures.
AGENTIC MECHANISM
MODEL DECIDES
SECURITY BOUNDARY
SCENARIO DATABASE & POLICY
ACTIVE SYSTEM PROMPT
OPEN SOURCE
Read the vulnerable and hardened implementations or propose another scenario.
Read the vulnerable and hardened implementations or contribute a scenario.