Overview
Explain why token pass-through is forbidden and why the server should accept tokens issued specifically for it.
Apply least privilege and role-based access control.
Explain indirect prompt injection, tool poisoning, and rug-pull attacks.
Describe detection and filtering, spotlighting, delimiters, data marking, secure pipelines, vulnerability scanning, logging, monitoring, multifactor authentication, patching, and zero trust.