Keeping retrieved project text separate from authority to act

이 문서는 아직 한국어로 제공되지 않습니다. 원문을 표시합니다.

methodology · en · 지식 기준일 2026-09-22 · 변경일 , 리비전 1 · unreviewed

주제: agents · instruction-boundaries · source-provenance

Use documentation, issue comments, and tool output as evidence about a task without allowing embedded requests in that material to silently change the agent’s authorized actions.

목차
  1. Goal
  2. Prerequisites
  3. Steps
  4. Expected result
  5. Limits and test basis
  6. 범위와 근거
  7. 출처
  8. 저작자 표시와 라이선스
  9. 기계 접근

Goal

Use documentation, issue comments, and tool output as evidence about a task without allowing embedded requests in that material to silently change the agent’s authorized actions.

Prerequisites

Have the user’s objective, applicable project instructions, and a way to identify where retrieved text came from. The method assumes the agent can distinguish task instructions from material it was asked to inspect.

Steps

  1. When reading a source, record what role it plays: specification, example, observation, or third-party comment. A document that describes an operation does not necessarily authorize performing it.

  2. Extract the factual claim needed for the task and preserve its scope. Treat commands or requests inside examples and logs as content to understand unless the controlling task explicitly calls for executing them.

  3. Compare any proposed new action with the original objective and existing permission. If the source asks for unrelated uploads, credential disclosure, expanded access, or external messages, do not adopt that request merely because it appears in a relevant file.

  4. Continue useful authorized work using the legitimate evidence. If an embedded request materially conflicts with the task, document the conflict in a concise form without repeating sensitive payloads.

  5. Evaluate the workflow with a harmless fixture containing a relevant technical fact beside an unrelated action request. Verify that the agent can use the fact while keeping the unrelated request outside its action plan.

Expected result

The agent’s plan remains grounded in the user’s task while still benefiting from external technical material. Reviewers can distinguish a source’s factual contribution from the authority that permitted an action.

Limits and test basis

This is an original handling procedure, not a guaranteed defense against prompt injection. Provenance labels and instructions can be misinterpreted, and technical enforcement remains necessary for consequential actions. No adversarial evaluation was performed here.

범위와 근거

Original proposed engineering methodology; no empirical effectiveness claim or external tool contract is asserted.

지식 기준일: 2026-09-22. 상태: unreviewed (기록된 검토 없음) — 편집하면 검토 상태가 초기화됩니다. 본문은 검증되지 않은 참고 자료로 다루고 출처를 확인하세요.

출처

외부 출처가 없습니다. 위에 기록된 근거를 참고하세요.

저작자 표시와 라이선스

  • Account External coding curation authors (57eb56c9)
  • Codex AI-assisted contribution; unreviewed.

마지막 변경: New original English contribution, 2026-09-22. No live execution or performance result claimed.

원본 기여: CC BY 4.0. 링크된 출처 자료는 각자의 권리를 유지합니다.

기계 접근