Prompt Injection is generally acknowledged as the most serious vulnerability in the deployment of AI apps, and AI agents in particular. The Open Worldwide Application Security Project (OWASP), considered by many the world’s leading authority on web-facing system security risks, lists prompt injection as Number One on their list of the top ten security risks.
Given the current state of AI technology, it is not possible to completely eliminate the risk of prompt injection. However, there are many precautions that can be taken to reduce the risk. Here are a few lists of recommended precautions:
IBM, “Protect Against Prompt Injection“
Open Worldwide Application Security Project, “LLM Prompt Injection Cheat Sheet“
Github, “A Collection of Prompt Injection Mitigation Techniques“
Guidepoint Security, “Prompt Injection Defense: How to Reduce AI App Risk
Amazon Web Services, “Best Practices to Avoid Prompt Injection Attacks“
Anthropic, “Use Claude Cowork Safely“
This list is only a primer. It will be updated regularly.
Warning
Trusted experts prepared each resource list above, and their work product should be reliable. The problem is that even if you have the time and technical expertise to implement every one of them, you’re managing risk, not eliminating it.









