--- name: ai-agent description: "Keep retrieved content, model output, tool authority, and user consent separate throughout an AI-assisted workflow." --- # Agents, MCP, and retrieval Keep retrieved content, model output, tool authority, and user consent separate throughout an AI-assisted workflow. Defensive study and review of artifacts supplied by their owner. Record missing evidence as an open question. ## Bring to the review - Tool definitions and granted scopes - Retrieval permissions and provenance metadata - Human approval and audit requirements ## Review guide ### 1. Model authority separately Document what the model may suggest, what a tool may do, and which identity authorizes the tool invocation. ### 2. Review retrieval boundaries Require authorization and provenance checks before tenant or sensitive documents reach context. ### 3. Validate before action Make tools independently validate typed arguments, resource scope, and policy rather than trusting generated instructions. ### 4. Make consent progressive Present meaningful scope at approval time and retain an audit trail for sensitive operations. ## What to produce - Authority and consent map - Retrieval boundary policy - Tool validation contract ## Common mistakes - Granting a broad token to a narrow task - Treating retrieved text as instructions - Equating a model error with an authorized security impact ## Reading and source context ### Resources - [MCP scope selection: progressive consent and accumulated authority](https://vulns.co/research/resources/mcp-progressive-scope-authority/) - [OWASP LLM08:2025: retrieval permissions and knowledge provenance](https://vulns.co/research/resources/owasp-rag-retrieval-permission-boundaries/) - [OWASP LLM05:2025: generated-output consumer trust](https://vulns.co/research/resources/owasp-llm-output-consumer-trust/) ### Diagrams - [Retrieved content is data, not authority](https://vulns.co/research/diagrams/ai-content-authority-separation/) ### Reports - [Gemini Enterprise connected-content trust failure allowed persistent-memory modification](https://vulns.co/research/reports/google-gemini-enterprise-connected-content-memory-integrity-2026/) - [Gemini-to-Colab rendering boundary exposed Workspace data](https://vulns.co/research/reports/google-gemini-colab-rendering-boundary-2025/) ## Provenance Editorial guide by vulns.co / GK Data. Updated 2026-10-11. Library snapshot: 2026-10-04; commit d5550c7891119cf1379e235721541c947850a3b3. The guide is an editorial synthesis. Linked records preserve their own sources and review dates. Reader: https://vulns.co/skills/ai-agent/