What information should never flow from untrusted content straight into tool execution?

Instruction: Explain what kinds of information require validation before tool use.

Context: Checks whether the candidate can explain the core concept clearly and connect it to real production decisions. Explain what kinds of information require validation before tool use.

Official answer available

Preview the opening of the answer, then unlock the full walkthrough.

Anything from untrusted content that can change a downstream action needs validation first. I especially worry about instructions, hidden directives,...

Related Questions