Separate data from authority

A retrieved page may instruct the assistant to ignore rules or send data. It arrived as reference material, not an authorized command. Reading it must not change permissions or approved destinations.

Enforce application controls

Restrict tools, destinations and fields, checking every action on the server. Separate reads from writes and review sensitive actions as appropriate. Minimize secrets and unrelated records in context to reduce exposure if the model mishandles content.

Test several entry points

Place hostile instructions in documents, search results, filenames and messages using synthetic data in an isolated environment. Observe actions and data exposure. Passing a test set establishes only the tested scope, not immunity to every attack.