Can untrusted user or retrieved content override intended instructions?
Technology / LLM applications
Prompt Injection Security Assessment
Evaluate direct and indirect prompt-injection paths across LLM applications, retrieval pipelines, agents, tools, and connected data sources.
01 / THE REVIEW QUESTION
Start with the system, data, and decision—not a generic checklist.
Prompt injection becomes materially more dangerous when model output can reach sensitive information, invoke tools, modify state, or communicate externally. Testing therefore has to follow the full application and agent architecture rather than the model prompt alone.
02 / Questions to answer
What a useful assessment should establish.
Can injected instructions reach tools, secrets, private data, or privileged actions?
Are output handling and authorization controls independent of model compliance?
Can suspicious prompt/agent activity be logged, reproduced, and contained?
03 / Assessment scope
What Ayliea examines.
Exact procedures are confirmed in writing before work begins. Technical testing is performed only when explicitly scoped and authorized.
01Direct and indirect injection testing when authorized
02Retrieval and external-content trust boundaries
03Tool and function-call authorization
04Sensitive-information disclosure paths
05Logging, guardrail, and containment evidence
04 / OUTPUT
Evidence and findings another reviewer can follow.
The deliverable separates what was observed or supplied from what was represented, unavailable, untested, or outside scope. That keeps the conclusion useful without overstating what the evidence proves.
Reproducible findings for tested paths
Affected data/tools and impact narrative
Evidence and testing limitations
Prioritized mitigations
Retest scope when included
05 / PRIMARY SOURCES
Built around the requirements and guidance that actually matter.
06 / SCOPE THE WORK
Have a real system or review question in mind?
Bring the AI system, the data it touches, the review trigger, and the evidence you already have. Ayliea will determine whether a Review, Assessment, or broader scope fits.