Agent Security: Prompt Injection, Permissions, Sandboxes, and Credentials
Untrusted content will influence the model, so the execution system must limit what that influence can achieve: what prompt injection, permissions and approvals, sandboxes, credentials, and MCP authorization each cover.