prompt-injection
Safeguard articles tagged "prompt-injection" — guides, analysis, and best practices for software supply chain and application security.
100 articles
Authorization Belongs in the Tool, Not in the Prompt
Your support chatbot can now issue refunds and look up orders, because someone connected it to real tools. Every one of those actions sits behind a customer-facing text box, protected however carefully the prompt was worded.
A Poisoned Memory Outlives the Conversation That Created It
Prompt injection in a single turn affects one response, then the next request starts clean. A persistent memory feature breaks that boundary by design, so a single successful injection becomes durable, recalled and trusted in every future session.
EchoLeak: The First Real-World Zero-Click Prompt Injection in a Production LLM
A single email, never opened or clicked, was enough to exfiltrate data from Microsoft 365 Copilot. CVE-2025-32711 shows why zero-click prompt injection is a categorically different threat than phishing-style attacks.
Indirect Prompt Injection Stopped Being a Demo. Google Is Measuring It at Web Scale.
Malicious injected instructions are now tracked across billions of crawled pages a month, every AI browser tested at Black Hat proved vulnerable, and one framework bug turned a prompt into RCE.
ChatGPT Atlas and the Permanent Browser-Agent Injection Problem
OpenAI shipped ChatGPT Atlas in October 2025 and admitted by December that prompt injection in AI browsers may never be fully solved. Defenders need a posture, not a patch.
You Cannot Defend an MCP Server You Do Not Know You Are Running
Tool poisoning is the most impactful client-side MCP vulnerability, and the defensive research is solid. All of it assumes you know which MCP servers you connect to. Almost nobody does.
Every AI Coding Tool Has the Same Vulnerability, and It Isn't a Bug
Sandbox escapes in Claude Code, critical CVEs in Cursor, a 10.0 in Gemini CLI, prompt injection in Copilot. Different vendors, one shared cause: the agent must hold elevated access to be useful.
Security risks of multi-agent AI systems collaborating au...
Multi-agent AI systems introduce security risks classic AppSec misses: agent-to-agent exploits, swarm failures, and orchestration trust gaps.
Security implications of AI browser agents that click, br...
AI browser agents click, browse, and pay with your credentials -- and prompt injection attacks like EchoLeak and CometJacking prove they can be hijacked to do it.
Securing computer-use AI agents that operate desktops and...
Computer-use AI agents can click, type, and log into any app on your desktop. Here is how computer use AI agent security actually works in practice.
Explaining Model Context Protocol and its expanding attac...
MCP security is now urgent: MCP servers grew from 700 to 16,000+ in a year, and most are unaudited. Here is the threat model and how Safeguard secures it.
How tool poisoning attacks compromise MCP tool descriptions
A single poisoned tool description can turn a trusted MCP server into a silent data-exfiltration channel. Here's how these attacks work — and how to stop them.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.