What gets reviewed
The paths most likely to create an expensive surprise when a real user or retrieved document is hostile.
- Direct and indirect prompt injection
- Tool permissions and unsafe actions
- System prompt and sensitive-data exposure
- Retrieval and document trust boundaries