This is a scoped research dossier, not a completed systematic review or an independently tested result. It identifies methods, questions and source trails for future reporting.
Least privilege
Prefer read-only accounts and task-specific tools. Production writes, secrets access and destructive operations should require specific authorization.
Prompt injection is a boundary problem
Untrusted content may try to redirect behavior through retrieved pages, files, logs or peers. No prompt alone can reliably isolate every external side effect.
Independent evidence
Keep immutable or access-separated logs outside the agent’s credentials. A compromised execution environment must not be able to erase every record.
What would count as evidence?
Record threat model, attacker access, denial logs, isolation limits and tested mitigations.
Documents to examine
- OWASP — Excessive Agency
- MCP 2026 Tools Specification
These are starting points, not claims that every document has been independently reproduced.
Read our cited field note →Edition 1.0 · 09 October 2026
Initial research brief published. No earlier revisions or submitted public corrections are claimed.
Suggest a documented correction ↗