Build a prompt firewall checklist
Create a prompt-security checklist using trust boundaries and STRIDE-style threat questions.
A finance Q&A bot reads invoices, vendor records, and email threads. The prompt says answer accurately and do not reveal confidential information, but the workflow also lets the model draft payment emails. Prompt firewall checklist: boundary, source, output, tool, approval, log, test The common trap is reviewing the prompt text as if clear wording were enough to secure retrieval, sensitive data, and downstream action. Boundary Mark system instructions, user request, retrieved invoices, vendor emails, and tool outputs as separate trust zones. This exposes where untrusted text could be mistaken for authority and where sensitive data enters context. Source Require provenance…
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in