About This Resource

Simon Willison explains how private data access, untrusted input, and external communication can combine into a prompt injection risk. The article uses this combination to assess the capabilities granted to AI agents.