Skip to main content
Jeden Skill in Manus ausführen
mit einem Klick

detect-tool-output-policy-bypass

Sterne3
Forks0
Aktualisiert9. Juli 2026 um 16:16

Detect MCP tool-call responses that try to override an agent's safety or approval policy. Consumes native or OCSF Application Activity records from ingest-mcp-proxy-ocsf and emits OCSF 1.8 Detection Finding (class 2004) when a `tools/call` response explicitly tells the agent to ignore instructions, bypass policy or guardrails, skip approval, or hide actions from the user. Use when the user mentions "tool-result prompt injection", "response-layer policy bypass", "MCP output tells the agent to ignore policy", or "indirect prompt injection via tool results". Do NOT use for tool descriptions, generic unsafe text, or semantic jailbreak claims.

Installation

Mit Codex oder Claude installieren Kopieren Sie diesen Prompt, fügen Sie ihn in Codex, Claude oder einen anderen Assistant ein und lassen Sie die Skill-Seite prüfen und installieren.

Datei-Explorer
4 Dateien
SKILL.md
readonly