Project overview
prompt-injection-review maps trust boundaries in LLM applications that use RAG, external content, tools, agents, or model-rendered output, tracing untrusted sources through the model to outbound actions, execution, data access, or UI sinks. It recommends least privilege, human approval, egress controls, structured validation, and authorization enforced in code. It explicitly treats prompt injection as having no complete fix: the goal is to contain what a successful injection can reach, not to rely on filters for false certainty.
Repository facts
- Primary language
- Not detected
- License
- MIT
- Repository updated
- Jul 10, 2026
- Default branch
- main
Resource types
General skill
Use cases
Security and privacy
Platforms
Claude Code, Codex, and more
Capabilities
Security guardrail