Skip to content

Agentic Covenants / Agentic Covenants Matrix

Content integrity at In-agent

This layer is advisory.

System-prompt hardening, instruction hierarchy, and provenance framing of untrusted content with a per-fetch nonce. Advisory, and weaker here than anywhere else in this matrix: prompt injection is an attack aimed precisely at this layer, so it is the one surface an adversary directly optimizes against. Reduces low-effort attacks so downstream scanners have less to score. Never cite it as a mitigation in a risk register.

How it is still bypassed

  • delimiter spoofing
  • multi-turn setup
  • cross-content collusion

Maps to

NIST CSF 2.0
(advisory)
NIST AI RMF
MEASURE 2.7
OWASP LLM
LLM01
OWASP Agentic
ASI02

Enforcement

controls/content-integrity/in-agent/