Agent prompt-injection and data-exfiltration tests
Author: joebudiCreated Jul 28, 2026Updated Sep 14, 2026
Create a repeatable security test suite proving that untrusted content cannot change an agent’s permissions or expose protected data.
Test instructions coming from:
- User messages.
- Knowledge documents.
- Web content.
- Tool and API responses.
- Encoded or obfuscated input.
Verify that this content cannot enable tools, change execution identity, bypass escalation, access unauthorised resources or extract protected information. Sensitive-data redaction and the product’s content-safety position should be separate tickets.
Source: Budibase/budibase