First, give conclusions that can be used for decision-making
The Agent risk comes from a combination of models, data, knowledge, tools and system privileges. The list of assets and threat model should be created before you go online, and direct and indirect tips should be checked separately, cross-user knowledge leaks, tool parameters overstepped, long-term certificates, malicious documents, external web pages, memory isolation, output execution and multiple Agent trust.
What conditions need to be identified before judgement is made?
The same question may have different answers under different business, data and project phases. It is suggested that the following conditions be checked and that the common findings on the web be incorporated into their own projects.
Suggested order of advance
First, we'll be clear about the target and the border.
Inventory models, knowledge, tools, identities and data flows.
Validation Key Dependence
(b) Establishment of threat models and test samples based on operational consequences.
Development of assessable outcomes
Exceeding authority, injection, abuse, disclosure and resumption of tests.
Make sure you decide the next step with the real results.
(b) Continuous re-examination after completion of overhaul, fixed regression and on-line.
How do you understand it in the actual business?
The procurement of Agent allows it to read quoted mail and create a procurement application. The security test not only asks if it will leak information, but also embeds instructions in an annex, attempts to modify the vendor account number, increase the amount, duplicate submission, and skip approval, and confirms that tool layers, approval, and whistleblowers can be validated.
The easiest pit to step on.
We'll use the security list of the regular chat robots.
Production permissions were tested in simulation tools but not validated
Not measured when the test is completed and the model or tool is upgraded
How should we end up receiving and confirming?
The report should include assets, versions, route of attack, evidence of recurrence, risk level, liability for correction and residual risk.
When preparing to communicate with suppliers or internal teams, it is recommended that current processes, representative samples, existing systems, planning time and budget levels be brought. First, the unknown items are clearly marked, and then the decision is made to use diagnostics, PoC, fixed-range projects or ongoing research and development, which is usually more reliable than a direct demand for a price and duration without borders.