Auditing The Lethal Trifecta

Find where an AI agent becomes dangerous: the trust context in which access to private data, exposure to untrusted content, and an ability to send data out all coexist. Any two legs are usually safe; all three let planted content make the agent read secrets and exfiltrate them. Use when designing or reviewing a tool-using LLM agent, before granting it a new tool or data scope, or to judge whether a prompt injection is actually exploitable. Covers capability inventory, the three legs, kill-chain construction, and which leg to cut.

UnboundCompute 1fede81 6.1 KB Updated

File contents

UnboundCompute/security-agent-skills/tree/main/skills/auditing-the-lethal-trifecta commit 1fede81ed1

Frequently asked questions

npx skillmds@latest add unboundcompute/auditing-the-lethal-trifecta