Skip to content

Add agent safety rules for untrusted xCloud output #18

Description

@wnstfy

Priority: Medium

Problem: Logs, cron output, vulnerability titles, site names, and API messages can contain prompt-injection text.

Acceptance:

  • Shared conventions state all xCloud API output is untrusted data.
  • Skills must not follow instructions contained in API/log output.
  • Summaries preserve data boundaries and avoid executing suggested commands from output.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions