# prompt.security > AI-optimized mirror of prompt.security containing 50 pages totalling 8,109 words of clean markdown content, structured data, and semantic HTML. Original source: https://prompt.security. Last updated: 2026-09-01T08:20:14.459Z. Each page is available as HTML (with JSON-LD structured data) and Markdown (text-only, ideal for LLMs and RAG). ## Homepage - [Prompt Security | From SentinelOne](/content/site-root.html): Comprehensive AI security resources for practitioners. Open-source tools, research, analysis, and guidance to understand and respond to AI threats. (329 words) ## Articles & Blog Posts - [Startup Map | Prompt Security](/content/ai-security-startup-map/index.html): Prompt's AI Security Startup Map., Interactive, continuously updated map of agentic AI security startups and vendors — runtime guardrails, agentic identity, AI red teaming, governance, and more. (839 words) - [When Your Repo Starts Talking: AGENTS.MD and Agent Goal Hijack in VS Code Chat | Prompt Security](/content/blog/when-your-repo-starts-talking-agents-md-and-agent-goal-hijack-in-vs-code-chat.html): VS Code auto-includes AGENTS.MD in every request. Learn how this hidden instruction layer can hijack agent goals and trigger data exfiltration. (189 words) - [Model Context Protocol (MCP) | AI Glossary | Prompt Security](/content/glossaries/model-context-protocol/index.html): The open standard that lets AI models connect to external tools and data. (9 words) - [When Your Plugin Starts Picking Your Dependencies: Marketplace Skills and Dependency Hijack in Claude Code | Prompt Security](/content/blog/when-your-plugin-starts-picking-your-dependencies-marketplace-skills-and-dependency-hijack-in-claude-code.html): Claude Code marketplace skills can rewrite how dependencies are installed. Demo shows silent httpx hijack and OWASP agentic failures. (115 words) - [Promptcast | Prompt Security](/content/promptcast/index.html): Welcome to PromptCast, the podcast of AI, Security and all the in between. Hosted by Itamar Golan, CEO & Co-founder of Prompt Security. (395 words) - [Prompt Security Top 10: Key Security Risks for MCPs | Prompt Security](/content/blog/top-10-mcp-security-risks/index.html): Discover the top 10 security risks in Model Context Protocols (MCPs). Learn how attackers exploit prompt injection, tool misuse, and more. (115 words) - [Denial of Wallet / Denial of Service | AI Glossary | Prompt Security](/content/glossaries/denial-of-wallet/index.html): Attacks that exploit LLM costs to degrade service or run up a huge bill. (75 words) - [Blog | Prompt Security](/content/blog/index.html): Read the latest news, research and insights on AI Security from the team at Prompt Security (373 words) - [blog/agentic-ai-expectations-key-use-cases-and-risk-mitigation-steps.html](/content/blog/agentic-ai-expectations-key-use-cases-and-risk-mitigation-steps.html) (318 words) - [Zeta Global: GenAI Unleashed and Security Challenges in the Era of User Empowerment | Prompt Security](/content/blog/zeta-global-genai-unleashed-and-security-challenges-in-the-era-of-user-empowerment.html): Zeta Global can pride themselves with having been early adopters of NLP and LLM technology, and released an LLM-based application called ZOE. (66 words) - [OWASP LLM Top 10: Key Security Risks for GenAI and LLM Apps | Prompt Security](/content/blog/the-owasp-top-10-for-llm-apps-genai/index.html): Review the OWASP LLM Top 10 list to understand the top security risks for GenAI and LLM applications. Learn key threats, examples & mitigation strategies. (190 words) - [EU AI Act | AI Glossary | Prompt Security](/content/glossaries/eu-ai-act/index.html): The European Union's foundational AI law, and the benchmark other regulations are measured against. (18 words) - [Why Browser Extensions Are the Only Scalable Way to Enable Safe GenAI Adoption — And Why Network Inspection Isn’t Enough | Prompt Security](/content/blog/why-browser-extensions-are-the-only-scalable-way-to-enable-safe-genai-adoption-and-why-network-inspection-isnt-enough.html): Browser extensions enable safe GenAI adoption at scale—real-time visibility, Shadow AI discovery, data redaction & user coaching. (112 words) - [Why AI Browsers Create a New, Unavoidable Security Risk | Prompt Security](/content/blog/why-ai-browsers-create-a-new-unavoidable-security-risk.html): AI browsers introduce structural security risks driven by prompt injection and autonomous actions. Learn why enterprises can't fully secure AI browsers, for now (115 words) - [When AI Trusts the Wrong Data: New Research From Prompt Security | Prompt Security](/content/blog/when-ai-trusts-the-wrong-data-new-research-from-prompt-security.html): Prompt Security reveals how AI systems can be silently manipulated by the very data they rely on, exposing a risk in modern AI pipelines. (106 words) - [The New Risk in Town: Shadow MCP Servers | Prompt Security](/content/blog/the-new-risk-in-town-shadow-mcp-servers/index.html): MCP servers let AI run commands, edit files, and send messages. Without control, they become a serious security risk. (106 words) - [AI Security | AI Glossary | Prompt Security](/content/glossaries/ai-security/index.html): The measures and controls that protect an organization from the risks of using AI. (40 words) - [AI Red Teaming | AI Glossary | Prompt Security](/content/glossaries/ai-red-teaming/index.html): Testing an AI app against real attack techniques before an actual attacker does. (58 words) - [What OpenClaw's (Clawdbot) Virality Reveals About the Risks of Agentic AI | Prompt Security](/content/blog/what-moltbots-virality-reveals-about-the-risks-of-agentic-ai.html): OpenClaw’s rapid adoption highlights a broader shift to agentic AI. This analysis examines what always-on AI agents change about risk, control, and deployment. (118 words) - [Prompt Injection 101 | Prompt Security](/content/blog/prompt-injection-101/index.html): Uncover real-world prompt injection examples and learn how these attacks work, why they’re hard to block & what you can do to protect AI systems. (121 words) - [Unicode Exploits Are Compromising Application Security | Prompt Security](/content/blog/unicode-exploits-are-compromising-application-security.html): Smiley face or threat? How emojis enable hidden LLM attacks via Unicode abuse. (103 words) - [Prompt Security Named as a 2025 Gartner® Cool Vendor in AI Security | Prompt Security](/content/blog/prompt-security-named-as-a-2025-gartner-cool-vendor-in-ai-security.html): Prompt Security is recognized as 2025 Gartner Cool Vendor in AI Security (103 words) - [The Agentic AI Attack Surface: Where Risk Lives Beyond the Prompt | Prompt Security](/content/blog/the-agentic-ai-attack-surface-where-risk-lives-beyond-the-prompt.html): Technical analysis of agentic AI security boundaries covering content ingestion, context translation, tool execution, and behavioral constraints in AI runtimes. (112 words) - [What Is AI Security? Risks, Challenges, and How to Stay Ahead | Prompt Security](/content/blog/what-is-ai-security-risks-challenges-and-how-to-stay-ahead.html): AI Security means protecting both employee use of AI tools and the apps you build. Discover key risks and how Prompt Security helps. (112 words) - [The Embedded Threat in Your LLM: Poisoning RAG Pipelines via Vector Embeddings | Prompt Security](/content/blog/the-embedded-threat-in-your-llm-poisoning-rag-pipelines-via-vector-embeddings.html): Prompt Security’s latest research details how embedding-level prompt injection can poison RAG pipelines, compromise model integrity, and evade detection. (109 words) - [AI Acceptable Use Policy | AI Glossary | Prompt Security](/content/glossaries/ai-policy/index.html): The ground rules for how employees can use AI tools and agents at work. (19 words) - [What is AI Red Teaming? The Ultimate Guide | Prompt Security](/content/blog/what-is-ai-red-teaming-the-ultimate-guide/index.html): Discover how AI red teaming helps secure AI systems by simulating adversarial attacks. Learn key techniques, tools, and best practices. (127 words) - [AI Risk Appetite: A Tale of Two CISOs | Prompt Security](/content/blog/ai-risk-appetite-a-tale-of-two-cisos/index.html): Our new GenAI app management offers a unique blend of dynamic detection of Shadow AI, easy onboarding and deployment, and advanced integrations. (154 words) - [ChatGPT Security Guide: Enterprise Risks, Incidents, and Practitioner Guidance | Prompt Security](/content/blog/chatgpt-security-guide-enterprise-risks-incidents-and-practitioner-guidance.html): What security teams actually need to know about ChatGPT: data handling, documented incidents, CISO guidance, and API risks. (122 words) - [Glossary | Prompt Security](/content/glossary/index.html): Navigate the world of GENAi security with our glossary of common security terms, and enhance your knowledge on key concepts. (459 words) - [AI Acceptable Use Policy | Prompt Security](/content/ai-acceptable-use-policy/index.html): Prompt Security provides comprehensive support to help your organization effectively implement and maintain its AI policies. (516 words) - [From Trivy to LiteLLM: Expanding the LLM Supply Chain Threat Model | Prompt Security](/content/blog/from-trivy-to-litellm-expanding-the-llm-supply-chain-threat-model.html): The Trivy breach and LiteLLM compromise show how LLM supply chain risk now extends from malicious packages to CI, middleware, prompts, and data. (115 words) - [Denial of Wallet in AI: When Cost Exhaustion Becomes Downtime | Prompt Security](/content/blog/denial-of-wallet-in-ai/index.html): Denial of wallet attacks exploit AI's usage-based pricing to inflate costs or degrade service. See how AI agents raise the stakes and what stops it. (106 words) - [Claude Computer Use: A Ticking Time Bomb | Prompt Security](/content/blog/claude-computer-use-a-ticking-time-bomb/index.html): Anthropic introduced "Claude Computer Use," a new AI model that enables Claude to autonomously control a computer, opening a new array of security risks. (106 words) - [8 Real World Incidents Related to AI | Prompt Security](/content/blog/8-real-world-incidents-related-to-ai/index.html): A list of 8 real world incidents related to AI from the past 24 months, highlighting the risk of using and deploying AI without safety and security measures (130 words) - [Case Study: Securing AI for Cymulate - Ensuring Safe AI Adoption Across Teams | Prompt Security](/content/blog/case-study-securing-ai-for-cymulate-ensuring-safe-ai-adoption-across-teams.html): Discover how Cymulate used Prompt Security’s real-time monitoring, dynamic policy enforcement, and low-latency AI protection to securely scale AI adoption. (73 words) - [AI Jailbreaking: When Bypassed Guardrails Reach Agents and Tools | Prompt Security](/content/blog/ai-jailbreaking-when-bypassed-guardrails-reach-agents-and-tools.html): A successful AI jailbreak doesn't stop at a bad response. See how agent permissions, connected tools, and runtime controls decide how far it actually reaches. (109 words) - [Case Study: Securing GenAI for Long-term Patient Care at Elder Outreach | Prompt Security](/content/blog/case-study-securing-genai-for-long-term-patient-care-at-elder-outreach.html): Elder Outreach installed Prompt Security to uncover shadow AI and sanitize sensitive data from the organization before employees would send it to GenAI tools. (40 words) - [Prompt Fuzzer - Open Source Security Testing Tool for AI Applications | Prompt Security](/content/fuzzer/index.html): Test and harden your AI prompts with our intelligent fuzzer. This free fuzzing engine uses evolutionary fuzzing techniques to identify vulnerabilities and improve AI app security. (266 words) - [How ISO/IEC 42001 and 42005 Work Together for AI Governance | Prompt Security](/content/blog/iso-iec-42001-42005-ai-governance/index.html): ISO/IEC 42001 sets up AI management systems; ISO/IEC 42005 guides AI impact assessments. See how the two standards work together, including for AI agents. (19 words) - [The Key Layer in AI Security: Browser and Endpoint Sensors | Prompt Security](/content/blog/the-key-layer-in-ai-security-browser-and-endpoint-sensors.html): SASE, proxies, and EDR/MDM are foundational, but AI needs more. Learn why browser and endpoint sensors enable real-time AI governance. (108 words) - [Prompt for Homegrown AI Apps](/content/solutions/homegrown-genai-apps/index.html): Unleash the power of AI in your homegrown applications without worrying about AI security risks. (217 words) - [Prompt for AI Code Assistants](/content/solutions/ai-code-assistants-developers/index.html): Adopt AI code assistants like GitHub Copilot and Cursor while safeguarding secrets, scanning for vulnerabilities, and maintaining developer efficiency. (119 words) - [When AI Agents Become the Supply Chain: Hidden Control Planes in Agentic Systems | Prompt Security](/content/blog/when-ai-agents-become-the-supply-chain-hidden-control-planes-in-agentic-systems.html): Three attack cases show how AGENTS.md files, marketplace skills, and dependencies give AI agents unauthorized authority, and what to test before trusting one. (104 words) - [Agentic AI Security and Governance](/content/solutions/agentic-ai-security-and-governance/index.html): Real time visibility, risk assessment and enforcement at the machine level for agentic AI systems. (335 words) - [ClawSec: A Security Skill Suite for OpenClaw Agents](/content/ai-security-tools/clawsec/index.html): ClawSec is an open-source security suite for OpenClaw agents, protecting against prompt injection, supply-chain attacks, drift, and unsafe agent behavior. (65 words) - [Agentic AI | AI Glossary | Prompt Security](/content/glossaries/agentic-ai/index.html): AI that plans and takes action toward a goal, largely on its own. (140 words) - [Prompt for Employees](/content/solutions/employees/index.html): Enable your employees to adopt AI tools without worrying about Shadow AI, Data Privacy and Regulatory risks. (130 words) - [AI Red Teaming](/content/solutions/ai-red-teaming/index.html): From discovery to remediation to runtime protection, Prompt Security's Automated AI Red Teaming identifies critical risks like prompt injection, data exposure, and unsafe agent behavior. (184 words) ## Resources - [Full Page Index](/index.html): Browse all cached pages with rich metadata - [About This Cache](/about.html): Methodology, technical details, and usage guidelines - [XML Sitemap](/sitemap.xml): Machine-readable sitemap for crawler discovery - [Robots.txt](/robots.txt): Crawler directives - [AgentSite Network](https://agentsite.network/network.html): Public index of AgentSites and their machine-readable resources