← All posts

Topic · 3 pieces

Containing prompt injection in AI agents

Prompt injection cannot be filtered out reliably, but its blast radius can be bounded. These pieces show how scoping an agent's authority limits what an injected instruction can make it do.

Article

Give your agent a valet key

SalesBleed leaked Agentforce CRM data without breaking an authorization check. Why AI agents need task-scoped authority, with a runnable Tenuo example.

  • AI agent security
  • Prompt injection
Read article →
Guide

Tenuo against the OWASP Top 10 for Agentic Applications

How Tenuo maps to the OWASP Top 10 for Agentic Applications with enforcement-focused coverage across ASI01-ASI10.

  • AI agent security
  • Prompt injection
Read guide →
Article

Your AI agent is authorized to do everything wrong

Why identity-based authorization fails when agents act autonomously, and what warrant-based authorization looks like.

  • AI agent security
  • Prompt injection
Read article →