Skip to content
← Learning paths

Lesson 5 / 6 · 2 minute read

Validate the whole action

Enforce schemas, permissions, and aggregate limits at the tool boundary.

By the end

Prevent a sequence of individually small operations from exceeding authorized scope.

Follow the boundary
  1. 01Task budget
  2. 02Tool arguments
  3. 03Schema validation
  4. 04Aggregate check
  5. 05Committed state

Valid syntax can still be unauthorized

A refund of $100 can satisfy the tool’s numeric schema while exceeding a $50 task limit. Validate argument types and values, then separately check authorization. Neither a valid schema nor a model’s justification proves permission.

Schema validation and authorization solve different problems.

Sequences change the result

Two $30 refunds each satisfy a per-call $50 cap, but their total is $60. Check the proposed operation against already committed state. Production systems also need atomicity and concurrency handling; this isolated sandbox executes a bounded sequence in order.

Enforce aggregate limits against committed state.

Keep the original task usable

The legitimate task is to refund $25. Blocking the refund tool entirely fails that task. Verify both a permitted refund and several over-limit variants, including split operations and malformed values. Report the scope and size of the suite with the result.

A passed suite is evidence for that suite, not a universal guarantee.

Check your understanding

Why does checking each refund independently leave a gap?

Choose one answer

Lesson completion is a self-recorded learning milestone on this device. Lab results are tracked separately.

Put it into practice

Make the boundary observable.

Start with an explicit action in the guided sandbox. Then explore the related mission’s execution mode and evidence.

Sources and further reading

These sources inform the concepts. Our examples and sandbox scenarios are original and synthetic.

OWASP LLM Top 10 — 2025 taxonomy ↗OWASP Agentic Top 10 — 2026 ↗