# Prompt injection: keep authority outside retrieved text

https://thiago.limaesilvatecnologia.com.br/en/artigos/prompt-injection-boundary/

Published: 2026-09-12

External documents may inform answers without granting permissions.

Content produced with AI assistance for Thiago Silva’s website. Independent editorial analysis; it does not represent clients or employers.

Reading-path month: April 2026

Collection published on September 12, 2026. Months organize the reading path; they are not earlier publication dates.

A short architecture article. The technical reference supports the topic; hypothetical scenarios and assessment proposals are editorial analysis, not accounts of personal implementations.

## The architecture decision

An assistant may encounter instructions in content it should merely consult. Architectural risk appears when that text influences tools, destinations or permitted-data decisions.

## Practical application

Editorial proposal: separate content analysis from action authorization. In a hypothetical research assistant, document deterministic decisions and those relying on the model.

## How to verify

Use synthetic documents containing conflicting instructions in testing. Assess final outcomes, including tool calls, rather than text alone. Evidence should show that untrusted content cannot expand authority, even when persuasive or obtained from a familiar source.

## Sources

- [OWASP — LLM Prompt Injection Prevention Cheat Sheet](https://cheatsheetseries.owasp.org/cheatsheets/LLM_Prompt_Injection_Prevention_Cheat_Sheet.html). Accessed: 2026-09-12.

[Profile: Thiago Silva | Cyber Architect](https://thiago.limaesilvatecnologia.com.br/en/perfil/)
