noCV
BTRIAGE-104 · Build draft assistance

Keep log content from issuing new tool instructions

Practice briefBugAdvanced

An error message contains text requesting privileged configuration reads.

Focused work estimate
3h + prerequisites
Priority in the scenario
High
Engineering practice
Prompt injection

Estimated field mix

  • Security50%
  • Applied AI50%

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

Your next step

Review it, then add it to your workspace.

The board opens an editable draft; nothing is saved until you confirm it. Sign-in and workspace permissions apply, and Demo boards remain ephemeral.

Project context

A fictional on-call team wants an assistant that joins alerts, deployment notes, and runbooks. Incomplete telemetry and hostile log content make unsupported conclusions dangerous.

Setup prerequisites

  • Author synthetic alerts, deployment records, and runbooks plus deterministic tool and model doubles.

Preceding work

Complete these dependencies, or supply their agreed outputs before taking this ticket.

Acceptance criteria

  • Treat log text as untrusted data.
  • Allow only declared read-only tools.
  • Validate every proposed tool call independently.

Implementation constraints

  • No shell, configuration writes, or remediation tools are exposed.

Verification to include

  • Summarize a benign failure record.
  • Inject a privileged instruction and verify no unauthorized call occurs.

Deliverables

  • Adversarial tool-use checks.

Rollout and recovery

Block provider output on policy failure and preserve sanitized diagnostics.

Value of the work

For the engineer: Practice constrained tool use, operational uncertainty, and traceable AI outputs.

For the team: Produce concise incident drafts that preserve source traceability and operator control.

Evidence boundaries

Outcome Evidence: Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.

Ownership Evidence: Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence.