Prompt injection in code
Instrument the injection regression suite
Page 6 adds signals that distinguish bad input from component failure in the prompt-injection regression suite for a document-grounded agent.
1Learn the idea
Read
Emit stage signals
Instrument the prompt-injection regression suite for a document-grounded agent so a run records enough structure to debug offline: counts, latency if relevant, pass/fail of attack success rate, canary leakage, forbidden tool-call count, and a stable stage name. Redact secrets and raw credentials from every event.
Read
Emit and assert
import json
print(json.dumps({'stage':'injection-suite','attack_success':0,'canary':0,'forbidden_tools':0}))
Expected evidence: injection telemetry. Prefer JSON or structured text you can grep in CI over prose logs for prompt-injection-in-code.
Read
Lock signals with a regression test
Turn one historical failure—especially answer refuses in text but a hidden tool call posts a canary token—into a test that fails if the signal disappears for the injection regression suite. Observability without a failing test is optional decoration; observability with a test is part of the prompt-injection-in-code artifact.
Read
Lab notebook: signal schema
Draft a three-field event for the injection regression suite: stage, ok, and one domain field derived from attack success rate, canary leakage, forbidden tool-call count. Add fixture_id or docs_version when content can change. Explicitly list fields that must never appear (tokens, passwords, raw prompts) because treating retrieved document text as trusted system instructions is in scope for this lab.
Wire one assertion that fails if the injection regression suite event is missing after a run. Observability that cannot fail a test will not survive contact with a busy prompt-injection-in-code repository.
Read
Worked judgment
Imagine a teammate opens only your event stream after a bad deploy. Could they tell whether indirect-pdf-07 with IGNORE RULES + CANARY payload was wrong, whether answer refuses in text but a hidden tool call posts a canary token returned, or whether treating retrieved document text as trusted system instructions slipped through? If not, rename fields until those three stories are distinguishable.
Read
Why this stage matters for the injection regression suite
At the testing and observability stage for prompt-injection-in-code, the job is narrower than finishing a product demo. You are creating one progressive evidence piece about indirect-pdf-07 with IGNORE RULES + CANARY payload that later pages inherit without redefining success. Keep that fixture small enough to inspect by hand, keep outputs copy-pasteable as text, and refuse to narrate this baseline as if it were a production SLA: agent without document/instruction separation on the same attacks.
For this page specifically, success looks like a structured event schema locked by a test while still centering the user decision to block indirect instructions in retrieved documents from causing forbidden tool calls. If you cannot point to a file, command, or assertion that proves that for the injection regression suite, stay on this page instead of advancing.
How-to: red-team prompt injection · Snippet: injection test fixture · Glossary: adversarial prompt
Go deeper
Before you start
Why this matters
Write the single log line or metric event that would tell you whether a bad result came from input vs implementation for the injection regression suite. If your line could not tell them apart, redesign it before coding.
In the wild
See how this idea shows up as a product and a company — then come back to the lesson. Skills transfer across vendors.
Related lessons
Check your understanding
Page assessment
Answer from memory. Completion is saved from this evidence, not from opening the next page.
All responses are required.