Term Kind Topic What it is
Capability Confinement Least-Privilege Agents, Trust Domain Separation, Action Authorisation concept Prompt Injection Defence Limiting what an agent is authorised to do rather than trying to prevent it from being misled - because a model cannot reliably distinguish instructions from data, so the security boundary must sit outside it.
Indirect Prompt Injection concept Prompt Injection Defence An attack in which malicious instructions are placed in content the model will later retrieve, rather than typed by the user.
Tool Authorisation Boundary Model as Untrusted Proposer, Authorise Outside the Model concept Prompt Injection Defence Authorising every tool invocation against the initiating user's own permissions, outside the model - because the model cannot distinguish instructions from data and no prompt-level defence is reliable.