Agent Security & Governance
📌 Planned placeholder page: this page is reserved for "Agent security and governance — threat models (indirect injection, tool abuse, memory poisoning, exfiltration), layered defense, approval gates and governance", and the content will be filled in progressively along with learning.
Planned Content
- [ ] Agent threat model: direct/indirect injection, tool abuse, memory poisoning, data exfiltration
- [ ] Layered defense: input / decision / execution / output
- [ ] Action policies: allow / require-approval / deny, parameter whitelists
- [ ] Sandboxing, least privilege, output DLP and audit trails
- [ ] Red-teaming in regression sets and the governance checklist
Next Steps
- [ ] Complete this page item by item against the planning checklist in the Domain Overview
- [ ] Add runnable examples and pitfall records for each entry
- [ ] Change the status from "Planned" to "Collected" when done
For writing guidelines, please refer to the Domain Overview.