Knowledge Hub / AI and agent security

AI & Agent Security

How do context, tools, identity and authority combine safely?

LLMs, retrieved context, agents, MCP and the security boundaries between them.

Last verified
2026-09-20
Review interval
30 days
Status
In review

01 / Overview

How do context, tools, identity and authority combine safely?

An AI-enabled system combines a model with application instructions, data, identity and tools. The model can propose or explain; the surrounding system must constrain authority, validate outputs and ground claims in verified project content.

Level
Intermediate
Units
1
Estimated time
26 min
What you will learn
    Know first
    • Security foundations
    • Identity and access
    Learning materials
      1. 01AI and agent security26 min
      Start topic

      02 / Learn

      Learn

      03 / Concepts

      Concepts

      Context boundaryai-context-boundary
      Instructions and untrusted data can enter the same model context without becoming equally authoritative.
      Tool authorityai-tool-authority
      The identity, permissions and policy applied to a tool call determine its real impact.
      Groundingai-grounding
      Retrieved project content supplies evidence; model fluency does not make a claim authoritative.

      07 / Security

      Security

      1. Retrieved content is data, not authority. Treat indirect instructions inside documents, pages and tool results as untrusted input.
      2. The deterministic lab engine—not a tutor model—must decide whether a structured learning action is allowed and whether it succeeded.

      08 / Troubleshooting

      Troubleshooting

      1. When an explanation conflicts with a project source, preserve the source, expose the conflict and route the content for review.

      09 / Quick checks

      Quick checks

      1. Which component should make the final decision to allow a tool action?

      10 / GRAPH

      Related concepts

      • Large language models
      • Retrieval-augmented generation
      • Prompt injection
      • Agents
      • Model Context Protocol

      Used in certifications

      These links reuse canonical knowledge; the certification page does not own or duplicate the topic.

      11 / Resources

      Resources

      12 / Sources and freshness

      Sources and freshness

      Last verified
      2026-09-20
      Review interval
      30 days
      Source version
      MCP 2026-07-28 · OWASP GenAI · MITRE ATLAS checked 2026-09-20