Which TWO security measures are most effective at preventing 'Prompt Injection' attacks that target the arguments of tools used by an agent?
By enforcing a rigid schema, the orchestrator ensures that the arguments passed to the tool conform to expected types and formats. This prevents attackers from injecting malicious scripts or unexpected commands into fields that should only contain simple data, such as numeric IDs or pre-defined string constants.
Why this answer
Prompt injection in tool arguments occurs when an agent processes untrusted data and passes it into a tool call that executes logic. Validating inputs against a strict schema and running the tool in an isolated environment are the primary defenses, ensuring that even if the agent is misled, the impact is contained.
Exam trap
Candidates often rely on 'system prompt instructions' to tell the model not to be hacked. This is ineffective against sophisticated prompt injection that bypasses textual constraints to manipulate tool arguments.