SAG / ARCHITECTURE NOTE
External Knowledge and Prompt Injection: How Not to Read Documents as Instructions
Treat web materials as analytical inputs, separate from task instructions and tool permissions. Competitor pages and uploads may contain text intended to change a model’s behavior. The richer the supporting evidence becomes, the more important the authority boundary around external text is.
What Is the External Knowledge Boundary?
It is the principle of treating web materials as analytical inputs and separating them from task instructions and tool permissions. This note frames the external knowledge boundary in terms of responsibility for inputs, transformations, and outputs rather than as a feature name. For analysis results to be trustworthy, there must be a clear connection between what materials were received, what was checked, and how far the conclusions can go.
Why Is This Technology Needed?
Competitor pages and uploads may contain text intended to change a model’s behavior. The richer the supporting evidence becomes, the more important the authority boundary around external text is.
Design Principles and Data Flow
Structurally separate documents from instructions, and limit tools to their approved scope. Design URL, format, and source validation for outputs alongside human review.
External document → Separate data from instructions → Validated analysis
At each stage, do not relabel the success of the previous stage as an achievement of the next. By maintaining records of material identifiers, time periods, and validation status throughout, you can locate where omissions and errors occurred and determine what needs to be checked again.
Connection to the SAG Architecture
SAG connects external sources to evidence and observations. This note provides defensive criteria for extending analysis adapters; it is not a certification that all attacks can be completely blocked.
SAG’s operational value lies in connecting these relationships to pages and questions, comparison results, and improvement tasks. Customers can review both what needs strengthening and the reasoning behind decisions, rather than looking only at numbers. Patterns requiring further application should be interpreted within the scope of the relevant paragraph.
Illustrative Example and Criteria for Judgment
Even when an illustrative document contains text telling you to ignore previous instructions, that text is part of the material under review. Do not accept it as an instruction to change account permissions or download or reporting approval procedures.
The example above is provided to explain structure and calculations; it is not a measured result for any specific customer. Actual reports should link the selected period, subject, observation conditions, and original records so that the same judgment can be checked again.
Practical Validation Checklist
| Flow stage | Items to check |
|---|---|
| External document | Boundary between data and instructions |
| Separate data from instructions | Output URL validation |
| Validated analysis | Tool permissions and human approval |
Check that the same meaning is maintained not only with normal inputs, but also with empty materials, duplicate materials, and materials with different conditions. Connecting validation items to task-completion criteria can narrow the gap between feature descriptions and actual operations.
Limitations and Points to Consider in Application
Blocking specific wording alone is not enough. Least privilege, output validation, and regression testing with attack cases must be operated together.
Research and Official Documentation
- OWASP LLM Prompt Injection Prevention Cheat Sheet — A security resource for reviewing boundaries between external content and instructions, and the principle of least privilege.
External materials provide background on the design topics above; they do not certify every SAG implementation or customer outcome. The interpretation of how to apply this note and its illustrative examples are organized according to SAG’s operational structure. Materials checked: 2026-10-06.
Further Reading and Feature Information
- Related architecture note
- Try a service connected to the external knowledge boundary
- Feature-specific FAQ
- Discuss implementation scope
How to Continue Reading About This Technology
Read about the problems each of SEO, AEO, GEO, entities, and JSON-LD addresses.
SAG / KNOWLEDGE LINKS
