Quellen: Agent-Sicherheit & Lethal Trifecta
Dieser Knoten hält fest, woher das Wissen für das Konzept Die Lethal Trifecta stammt. Die Aufbereitung steht dort; hier liegen die geprüften Originalquellen mit den Kernzitaten.
1. 🎙️ Die Quellen im Überblick
| Quelle | Wer | Kernbeitrag |
|---|---|---|
| The lethal trifecta | Simon Willison | die drei Zutaten, “95% is a failing grade” |
| Designing agentic loops | Simon Willison | “wrecking its environment”, pragmatischer Umgang |
| Top 10 for LLM Applications | OWASP | Referenzliste der LLM-Risiken |
2. 🧷 Kernaussagen
Willison benennt die Konstellation und ihre Wurzel:
“The lethal trifecta of capabilities is: Access to your private data … Exposure to untrusted content … The ability to externally communicate … If your agent combines these three features, an attacker can easily trick it into accessing your private data and sending it to that attacker.” “LLMs are unable to reliably distinguish the importance of instructions based on where they came from.”
Zur Wirkungslosigkeit prozentualer Guardrails:
“in web application security 95% is very much a failing grade.”
Und das Designbild (Willison zitiert Solomon Hykes):
“An AI agent is an LLM wrecking its environment in a loop.”
3. 🔗 Was daraus kompiliert wurde
- Die Lethal Trifecta (das Konzept mit den Gegenmassnahmen)
📚 Weiterführende Links & Quellen
- Die Lethal Trifecta (die aufbereitete Konzept-Seite)
- Das Konzept: LLM-Wiki trifft OKF (warum Quellen separat liegen)
- Artikel: Simon Willison, The lethal trifecta (2025)
- Artikel: Simon Willison, Designing agentic loops (2025)
- Referenz: OWASP Top 10 for LLM Applications