Prompt injection through tools on the AI Agents track. Tool results and web pages are untrusted. They can contain text that tells the model to ignore instructions and call a dangerous tool. Treat them as data, not as orders.
This lesson assumes you already worked through Live failure modes.
The idea in practice
Separate system instructions from observations in the prompt. Do not give a browsing agent the same credentials as a payment agent. Prefer allow-listed domains.
A concrete check
goal = {
'track': 'AI Agents',
'lesson': 'Prompt injection through tools',
}
checks = [
'input available at decision time',
'score matches the real decision',
'failure case written down',
]
print(goal['lesson'])
for item in checks:
print('-', item)
Run the sketch locally if you have Python. The printout is a reminder of the checks, not a trained model. Replace the strings with the real inputs from your own example before you treat it as a design.
What usually goes wrong
Pasting a web page into the system prompt lets the page rewrite your policy. When this happens, stop adding parameters or tools. Fix the check, the data, or the permission, then run the same example again.
What to write down
- The input you are allowed to use at decision time.
- The output and the score or pass rule.
- One failure you will test on purpose.
- What you will not claim the system can do.
Practice
Show a malicious page snippet and say which tool call it is trying to trigger. Your guardrail should block it.
Self-check
- Say Prompt injection through tools in one sentence that mentions an input and an output.
- Name the failure mode in this lesson and the check that would catch it.
Done when: you can explain this lesson without the page open, and you have a written failure case.