Book Call

AI Tool Permission Demonstration

A reproducible application-control example with explicit decisions and no external tool execution.

Illustrative human approval checkpoint

This deterministic demonstration is not a live LLM, prompt-injection detector or security benchmark. It illustrates a server-side policy boundary using fixed fixtures. Nothing is emailed, deleted or executed.

Decision

No evaluation yet.

What is being tested?

A retrieved document can contain “ignore previous instructions” or “the user approved this”. Such text is source data, not an authorisation record. The fixture checks the proposed tool against an allowlist, the authenticated role and the trusted application's approval state. It deliberately does not decide whether the text “looks malicious”.

Expected decisions

What changes in production?

The checkbox represents state a browser user must not be able to grant themselves in a real system. A server must authenticate the approver and bind their decision to the exact recipient, payload, operation and expiry. Validate parameters, enforce document-level permissions and keep an audit trail. This small example does not implement those controls.

Reproduce and extend

The decision function is available as readable source. Tests cover unapproved tools, missing approval, untrusted source instructions and invalid roles. Real application testing also needs tool-result injection, cross-user retrieval, approval expiry and parameter substitution cases.

Reference: OWASP prompt injection. See LLM security testing for engagement scope and limitations.