Agentic Covenants / Agentic Covenants Matrix
Content integrity at In-agent
This layer is advisory.
System-prompt hardening, instruction hierarchy, and provenance framing of untrusted content with a per-fetch nonce. Advisory, and weaker here than anywhere else in this matrix: prompt injection is an attack aimed precisely at this layer, so it is the one surface an adversary directly optimizes against. Reduces low-effort attacks so downstream scanners have less to score. Never cite it as a mitigation in a risk register.
How it is still bypassed
- delimiter spoofing
- multi-turn setup
- cross-content collusion
Maps to
- NIST CSF 2.0
- (advisory)
- NIST AI RMF
- MEASURE 2.7
- OWASP LLM
- LLM01
- OWASP Agentic
- ASI02