Produce and evaluate a review-ready security package for an AI agent with MCP tools.
Run a controlled indirect prompt injection, observe an unsafe policy, add enforcement, and verify the blocked action.
Map agent authority, data origins, side effects, and approval points before connecting tools.
#prompt injection
Design MCP tools, authorization, input checks, and transport boundaries for least-privilege agent access.
Log agent decisions, detect policy failures, stop unsafe runs, and recover with evidence.
Test your understanding of agent authority, MCP tools, prompt injection, approval, logging, and recovery.