Standard / soft law
Untrusted external content should not flow into agent instructions or tool calls without mediation
Per OWASP LLM01 (Prompt Injection), untrusted external content (from websites, files, tool outputs, retrieved documents) must not flow unsegregated into an LLM's instruction context, since indirect prompt injection can alter model behavior, exfiltrate data, or trigger unauthorized tool calls. Mitigations: segregate and clearly denote untrusted content, enforce least-privilege tool access, and require human approval for high-risk actions. Detect a path where external/untrusted content reaches agent instructions or tool-invocation without segregation or privilege controls.
ai-security.untrusted-input-to-agent-instructions-or-tools · OWASP Top 10 for LLM Applications (2025) — LLM01: Prompt Injection · official source · jurisdictions: INTL