S-13Agent-to-Agent Trust
One agent’s output is another agent’s untrusted input — and internal provenance is not trust.
Further reading
- Why Do Multi-Agent LLM Systems Fail? Cemri et al., 2025
- Not what you’ve signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection Greshake et al., AISec 2023
- Design patterns for securing LLM agents against prompt injections Simon Willison, 2025