Quellen: Agent-Sicherheit & Lethal Trifecta

Dieser Knoten hält fest, woher das Wissen für das Konzept Die Lethal Trifecta stammt. Die Aufbereitung steht dort; hier liegen die geprüften Originalquellen mit den Kernzitaten.

1. 🎙️ Die Quellen im Überblick

QuelleWerKernbeitrag
The lethal trifectaSimon Willisondie drei Zutaten, “95% is a failing grade”
Designing agentic loopsSimon Willison“wrecking its environment”, pragmatischer Umgang
Top 10 for LLM ApplicationsOWASPReferenzliste der LLM-Risiken

2. 🧷 Kernaussagen

Willison benennt die Konstellation und ihre Wurzel:

“The lethal trifecta of capabilities is: Access to your private data … Exposure to untrusted content … The ability to externally communicate … If your agent combines these three features, an attacker can easily trick it into accessing your private data and sending it to that attacker.” “LLMs are unable to reliably distinguish the importance of instructions based on where they came from.”

Zur Wirkungslosigkeit prozentualer Guardrails:

“in web application security 95% is very much a failing grade.”

Und das Designbild (Willison zitiert Solomon Hykes):

“An AI agent is an LLM wrecking its environment in a loop.”

3. 🔗 Was daraus kompiliert wurde