InfoSec — AppSec & Security Engineering
Owner: AppSec or security engineering, whoever owns your SDLC security gate
What can be reached and what happens when someone abuses it. That is the actual blast radius of a compromised prompt, key, or session.
- No tool allowlist. The agent can call anything a session with its credentials could call, not a scoped subset.
- No answer for what a compromised or malicious prompt could make the agent do downstream
- Secrets or credentials reachable from the same context windowThe context window is the maximum text, measured in tokens, a model can consider at once. the model reads untrusted content in