
A malicious repository could turn Amazon Kiro into a data-exfiltration path
A Kiro prompt-injection flaw shows how repository content can steer an AI coding agent towards sensitive files, configuration changes and data exfiltration.
Read article
Google analytics are off.
Promptective journal / Topic index
5 journal entries tagged AI security.

A Kiro prompt-injection flaw shows how repository content can steer an AI coding agent towards sensitive files, configuration changes and data exfiltration.
Read article

Promptective now supports Amp.
How Amp’s plugin architecture and Orb identity helped Promptective bring managed policy to direct prompts, tool calls and tool results.
Read news

Safer inputs, retrieval, outputs and tools.
A practical guide to LLM security in production: control prompts, retrieval, outputs and tools; minimise sensitive evidence; test and respond.
Read guide

Bound permissions and hold consequential actions for approval.
Learn how to reduce prompt injection, tool abuse, and MCP risks with practical controls for LLM agents and their connected systems.
Read guide

How it works and how to reduce the risk.
Learn how prompt injection attacks work, see practical examples, and compare controls for protecting LLM applications in this 2026 guide.
Read guide