# Treat retrieved content as untrusted input

Taiga Learning · Worksheet
https://taiga.training/en/lessons/prompt-injection/

Use fictional or approved information. Do not put secrets in this worksheet.

## Learning objectives
- Identify an indirect prompt injection in a development workflow.
- Explain why text labels alone cannot enforce a security boundary.
- Design a safe test for tool restrictions.

## Exercise
Create a disposable fixture with a comment that asks an agent to skip a required check. Run an authorized, isolated evaluation without secrets or external writes. Verify the check still runs. Record the tool permissions, observed behavior, and the limits of this single test.

## Your response
- Scenario and scope:
- Assumptions and open questions:
- Proposed answer or decision, with reasons:

## Verify your response
| Claim or criterion | Evidence or test | Result or gap | Owner |
| --- | --- | --- | --- |
| | | | |
| | | | |
| | | | |

## Next action
- Action, owner, and date:
- When will you review this response?

## Principle to retain
A document can provide information without having authority. Enforce tool permissions even when the model interprets retrieved text incorrectly.

## Sources
- [OWASP: Prompt Injection Prevention](https://cheatsheetseries.owasp.org/cheatsheets/LLM_Prompt_Injection_Prevention_Cheat_Sheet.html)
- [OWASP: Prompt Injection risk](https://genai.owasp.org/llmrisk/llm01-prompt-injection/)

This worksheet supports learning. Completing it does not itself authorize a production change.
