Being allowed to act and being trustworthy as input are two different questions. My post-mortem from a bot security exercise and some quirky lessons on some fundamental (aka basic) shit.
uncommonengineer.com
AI Trust-Model Decomposition Failure in an Agentic Security Design | The Uncommon Engineer
Post-mortem on an LLM-assisted Discord bot security design where high factual accuracy masked a single-axis trust model — authorization and input integrity were conflated.