$less ~/slides/securing-ai-agents-in-practice
// deck 02 · SIGS — Security Interest Group Switzerland
From Prompt Injections to Rogue Actions
Securing AI Agents in Practice
1 / 76
skip thumbnails
// key slides
// what you take away
- Nothing known stops a model acting on an injected prompt, so layer the defenses.
- A poisoned booking page leaks a door code through a markdown image URL.
- A policy engine asks the user before a destructive tool call goes through.























































































































































