Inspect agent input
Evaluate user messages, system context, retrieved content and files before they enter a supported inference path.
Google analytics are off.
AI agent security
Promptective checks supported agent inputs, generated output, tool requests and external actions before delivery or execution.
Evaluate user messages, system context, retrieved content and files before they enter a supported inference path.
Check generated text, code and structured results before your application delivers or acts on them.
Apply policy before supported tools read data, change systems or create an external side effect.
Protection coverage
Agent integrations can protect inputs, generated output and proposed actions when the application sends them to Promptective before delivery or execution.
Credentials, PII, financial and health data, customer information, proprietary context and other policy-defined content.
Direct and indirect instructions that try to override policy, extract hidden context or manipulate the agent through retrieved data.
Supported unsafe code, commands, links, packages, secrets and other findings while the application still holds the result.
File, shell, Git, deployment, credential, infrastructure, network and external-side-effect requests before execution.
Amp integration
SupportedPromptective checks supported Amp direct prompts before onward inference, tool calls before side effects and tool results before they return to the model.
Read how we built Amp supportApply organisation policy before a supported direct message continues into model inference.
Allow, transform or stop a supported tool request while Amp still holds the proposed action.
Check held structured results before Amp supplies them to the model for its next step.
Cloud Analysis
Supported direct prompts, tool calls and held tool results receive organisation policy at Amp’s lifecycle hold points. Routine receipts keep content-minimised policy, decision, reason and checkpoint facts for each protected interaction.
Practical control model
Cover the context an agent trusts, the data and tools it can reach, and the effects it can create.
Record the agent’s purpose, data, models, tools, users, accountable owner, foreseeable misuse, acceptance criteria, and stop conditions.
Give the agent only the tools, data, destinations, credentials, and duration needed for the task. Require fresh human approval for high-impact or irreversible actions.
Apply policy to user input, retrieved content, tool results, generated output and proposed actions before delivery or execution.
Test prompt injection, tool misuse, permission failures, unsafe output, and recovery paths before deployment, then retain bounded evidence and review material changes.
Questions and answers
AI agent security protects the model-driven loop that accepts context, plans work, generates output, selects tools, uses memory, and requests external actions. It combines AI-specific risk controls with identity, least privilege, input and output validation, approval, isolation, monitoring, and incident response.
A chat-only assistant mainly returns content, while an agent can retrieve data, call tools, use credentials, change systems, and trigger external effects. Those capabilities add identity, authorisation, tool integrity, execution, memory, and action-approval boundaries. A chatbot with tools should be assessed as an agent for those interactions.
Give each agent a distinct identity, minimum permissions, an allowlist of necessary tools and destinations, validated arguments, bounded credentials, and a policy check before execution. Require fresh human approval for destructive, privileged, irreversible, or externally visible actions, and record the decision and outcome without retaining unnecessary sensitive content.
No single prompt, model, or filter can guarantee prevention of every direct or indirect prompt-injection attack. Reduce likelihood and impact by treating retrieved content and tool results as untrusted, limiting permissions, separating data from instructions, checking proposed actions, isolating execution, testing realistic attacks, and requiring approval for high-impact effects.
Promptective can block an AI agent action when a supported integration sends it for checking before content delivery or execution. Policy can allow, audit, redact, require approval or block the request. Other discovered activity is recorded for review.
Yes. Promptective uses Amp’s supported lifecycle hooks to check direct prompts before onward inference, tool calls before side effects and tool results before they return to the model. At these three hold points, organisation policy is applied and routine records keep content-minimised decision and checkpoint facts.
Retain bounded facts that can reconstruct the control decision: the agent and principal, policy version, interaction stage, tool or action class, finding types, decision, approval, protection status, and delivery or execution outcome. Routine Promptective evidence excludes prompt, response, tool-argument, and tool-result plaintext.
References
These sources were checked on 21 August 2026. Agent threats, protocols, and standards are evolving; recheck their status when designing or reviewing a production system.
Australian Government, National AI Centre
Current Australian guidance covering accountability, AI-specific risk management, testing and monitoring, cybersecurity, records, and human control.
OWASP GenAI Security Project
The December 2025 community framework identifies agent goal hijack, tool misuse, identity and privilege abuse, supply-chain risk, and other agentic threats.
US National Institute of Standards and Technology
NIST announced active work on AI agent security, identity, authorisation, and interoperability in February 2026. The initiative is not itself a final security standard.
Deployment and evidence
Use the same organisation policy across supported inputs, generated output, tool requests and external actions.
Apply versioned rules consistently across supported inputs, outputs, tool requests and actions.
Record whether content or an action was held, changed, delivered or blocked.
Require authorised review before sensitive or high-impact supported actions continue.
Send bounded decision and delivery facts to the control plane without routine prompt, response or tool-result plaintext.