<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Agents on Feng&#39;s Notes</title>
    <link>https://ofeng.org/tags/agents/</link>
    <description>Recent content in Agents on Feng&#39;s Notes</description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Sun, 23 Aug 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://ofeng.org/tags/agents/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>How to Design a Secure AI Agent: Make Unsafe Actions Impossible</title>
      <link>https://ofeng.org/posts/designing-a-secure-ai-agent/</link>
      <pubDate>Sun, 23 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://ofeng.org/posts/designing-a-secure-ai-agent/</guid>
      <description>&lt;p&gt;The hard part of securing an AI agent is accepting a slightly uncomfortable premise: &lt;strong&gt;prompt injection is not a bug we can reliably filter away.&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;An agent reads natural language from multiple places—user requests, emails, web pages, PDFs, search results, tickets, and tool responses. The model cannot reliably tell which of those words are authoritative instructions and which are merely data. A malicious document can therefore try to redirect the agent into revealing data, sending a message, changing infrastructure, or making a purchase.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
