A valid login is not a permission check
Follow one request from identity to resource access, and find the security decision that authentication alone cannot make.
Follow your curiosity from the first principle to the next attack surface. Clear explanations, hands-on experiments, and the notes that connect it all.
Context is not authority. Retrieved text can inform an answer. It should never grant new permissions.
Ideas worth sitting with.
Notes worth coming back to.
A closer look at indirect prompt injection, the RAG trust boundary, and why retrieved content should never inherit authority.
Follow one request from identity to resource access, and find the security decision that authentication alone cannot make.
A practical starting point for threat modeling: identify the assets, follow the data, and ask where trust changes.
Look past the tool description. What can the agent actually do, with whose identity, and under which constraints?
A small template for turning an interesting result into a useful experiment: setup, observation, explanation, and limits.
4 notes to explore
Start at the foundations, follow a thread,
or jump into something unfamiliar.
What happens when a document gives an agent instructions? Change the input. Test the boundary. See the decision for yourself.
Step into the playground One small experiment. A much bigger idea.A model can propose an action.
The application decides what is allowed.
Unhurried reading. Adjustable text and paper tones. Room to think, and a clear path to the next question.
Learn something. Test it. Write it down.
Help the next person connect the dots.