Skip to main content

Posts

Showing posts with the label Context Engineering

Agent Security: Test an Injected Tool Result

Testing an injected tool result means deliberately placing harmless, untrusted instructions inside data returned by a tool and then verifying that the agent treats that content as data rather than as an instruction.   This matters because a tool result can look legitimate—the tool itself may be trusted, the API call may be authenticated, and the returned data may appear perfectly normal—while the actual content inside that result can still be hostile or misleading. 🔐 For an agent, the security question is therefore not simply “Did the tool call succeed?” It is “What happened after the tool returned data?” A compromised or manipulated result can influence subsequent decisions, trigger another tool, expose information, or cause an unintended business action. Current guidance from Microsoft and OpenAI emphasizes treating tool-provided or otherwise untrusted content carefully and enforcing controls at the boundary where that content can influence actions. 🛡️ Core idea A tru...

How to Evaluate Context Engineering: A Practical Guide to AI Agent Context

Context engineering is the disciplined design, assembly, control, and observation of the information an AI agent is allowed to work from at each stage of a task. That includes standing rules, approved tools, retrieved information, session state, memory, task history, and hand-offs between agents or workflow steps. The important question is not simply whether context exists; it is whether the right context reaches the right step, from the right source, with the right trust level, at the right time, under the right permissions . 🧭 This matters because context is part of the agent's operating environment. A stale record can send an action in the wrong direction. A broad tool permission can turn an otherwise harmless misunderstanding into a real side effect. A memory item without provenance can be reused long after the original situation has changed. Current platform and security guidance therefore treats context providers, tools, sessions, external data, approvals, tracing, ...