Choose the safe response when untrusted calendar content attempts to change an AI agent's task.
The assistant is reading a vendor invite and can also edit the calendar. What should Lena do before allowing the assistant to update the meeting? Summarize logistics only, ignore source-authored instructions, and flag the attendee-change request for review. Right. This preserves the OWASP LLM01 trust boundary: outside content can inform the summary, but it cannot authorize tool actions. Let the assistant add the outside attendee because the request was inside the invite. Weaker. That treats untrusted invite content as an operating instruction and gives the external sender control over the calendar tool. Ask the vendor to resend the invite in…
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in