Threat scenarios

Prompt Injection & Private Data Leakage Risks

Untrusted content can attempt to redirect an agent’s retrieval and export behaviour.

EndigitalX editorialReviewed

Illustrative scenario

A retrieved document tells the agent to gather private records and submit them to an external location. Retrieval permissions and output destinations determine the potential impact.

This is a generalised threat scenario, not a claim about a named incident or an EndigitalX client.

Controls to examine

Minimise retrieval scope, isolate sessions and tenants, restrict destinations and tools, and log enough to investigate without duplicating sensitive records.

Testing boundary

Use synthetic data and an authorised test environment. Agree allowed actions and stop conditions before testing; never treat this brief as permission to probe someone else’s systems.

A bounded export test

Place a conflicting export instruction in a synthetic document an agent is allowed to retrieve. Use a controlled destination and records with no real personal information.

Test whether the agent attempts a broader retrieval or export, and whether destination and record limits are enforced outside the model. Capture the policy decision as well as the model output. Repeat with an ordinary permitted request to check that the control does not simply block all work.

State the document types, retrieval paths and destinations tested. Untested connectors and data sources remain outside the result.

Start with a clear scope

Tell us which systems, actions and review requirements are in scope. We will discuss the work, responsibilities and deliverables before you commit.