Activity v1

Prompt-Injection Threat-Model Exercise

Classify direct and indirect injection paths then assemble independent authorization isolation validation and response controls.

rubric
beginner
seed 11

Prompt-Injection Threat-Model Exercise: Baseline

Explore the core controls with stable inputs and visible assumptions.

Assumptions

The simulation is deterministic and intentionally simplifies provider and hardware behavior.

Failure injection

Stable baseline with no injected production fault.

Control objective

Select the control that breaks the attack path. Prompt instructions alone do not create an authorization boundary.

0 of 4 decisions recorded
0%
1. A retrieved document tells the model to upload secrets.
2. User input contains encoded instructions that become active after transformation.
3. An untrusted server advertises a misleading tool description.
4. Tool arguments change after the user approves the operation.
0 saved attempts

Expected outcomes

  • Identify trust boundaries and attack paths
  • Select controls outside model instructions

Connected concepts

Apply this lab in an architecture