1. Build the source-sink model
Outcome: Every attacker-controlled input and consequential sink has an explicit trust boundary.
Tasks
- →Inventory user, web, RAG, tool, and memory sources
- →Mark secrets, write tools, and external egress sinks
- →Link source → interpreter → sink paths
- →Define where deterministic policy must stop an action
Checks
- ✓No source lacks a trust classification
- ✓Write or egress sinks are not protected only by a system prompt