Skip to the content.

10. Trust, security, and the untrusted input problem

Draft.

When agents do the work, every piece of text entering the system is a potential instruction. This is not a hypothetical for us: our own inbox is publicly reachable.

The architecture we run and will document here: