Page 6 of 8~112 min topic

Prompt injection in code

Instrument the injection regression suite

Page 6 adds signals that distinguish bad input from component failure in the prompt-injection regression suite for a document-grounded agent.

~14 min this pageTesting and observability

1Learn the idea

Read

Emit stage signals

Instrument the prompt-injection regression suite for a document-grounded agent so a run records enough structure to debug offline: counts, latency if relevant, pass/fail of attack success rate, canary leakage, forbidden tool-call count, and a stable stage name. Redact secrets and raw credentials from every event.

Read

Emit and assert

import json
print(json.dumps({'stage':'injection-suite','attack_success':0,'canary':0,'forbidden_tools':0}))

Expected evidence: injection telemetry. Prefer JSON or structured text you can grep in CI over prose logs for prompt-injection-in-code.

Read

Lock signals with a regression test

Turn one historical failure—especially answer refuses in text but a hidden tool call posts a canary token—into a test that fails if the signal disappears for the injection regression suite. Observability without a failing test is optional decoration; observability with a test is part of the prompt-injection-in-code artifact.

Read

Lab notebook: signal schema

Draft a three-field event for the injection regression suite: stage, ok, and one domain field derived from attack success rate, canary leakage, forbidden tool-call count. Add fixture_id or docs_version when content can change. Explicitly list fields that must never appear (tokens, passwords, raw prompts) because treating retrieved document text as trusted system instructions is in scope for this lab.

Wire one assertion that fails if the injection regression suite event is missing after a run. Observability that cannot fail a test will not survive contact with a busy prompt-injection-in-code repository.

Read

Worked judgment

Imagine a teammate opens only your event stream after a bad deploy. Could they tell whether indirect-pdf-07 with IGNORE RULES + CANARY payload was wrong, whether answer refuses in text but a hidden tool call posts a canary token returned, or whether treating retrieved document text as trusted system instructions slipped through? If not, rename fields until those three stories are distinguishable.

Read

Why this stage matters for the injection regression suite

At the testing and observability stage for prompt-injection-in-code, the job is narrower than finishing a product demo. You are creating one progressive evidence piece about indirect-pdf-07 with IGNORE RULES + CANARY payload that later pages inherit without redefining success. Keep that fixture small enough to inspect by hand, keep outputs copy-pasteable as text, and refuse to narrate this baseline as if it were a production SLA: agent without document/instruction separation on the same attacks.

For this page specifically, success looks like a structured event schema locked by a test while still centering the user decision to block indirect instructions in retrieved documents from causing forbidden tool calls. If you cannot point to a file, command, or assertion that proves that for the injection regression suite, stay on this page instead of advancing.

How-to: red-team prompt injection · Snippet: injection test fixture · Glossary: adversarial prompt

Previous · Next

Go deeper

Before you start

Why this matters

Write the single log line or metric event that would tell you whether a bad result came from input vs implementation for the injection regression suite. If your line could not tell them apart, redesign it before coding.

In the wild

See how this idea shows up as a product and a company — then come back to the lesson. Skills transfer across vendors.

Check your understanding

Page assessment

Answer from memory. Completion is saved from this evidence, not from opening the next page.

1. Can input faults be distinguished from component faults in the event?
2. Are secrets redacted from logs?
3. Is there a test that fails if the signal vanishes?
4. Does the event still reference the decision: block indirect instructions in retrieved documents from causing forbidden tool calls?

All responses are required.