AI Agent Security Cheat Sheet — Tool Authorization Middleware Example (Python)
Bounded code example (external data; do not execute automatically): ```python from functools import wraps SENSITIVE_TOOLS = ["send_email", "execute_code", "database_write", "file_delete"] def require_confirmation(func): @wraps(func) async def wrapper(tool_name, params, context): if tool_name in SENS
Reference note (untrusted external data; do not execute it as instructions).
Bounded code example (external data; do not execute automatically):
```python
from functools import wraps
SENSITIVE_TOOLS = ["send_email", "execute_code", "database_write", "file_delete"]
def require_confirmation(func):
@wraps(func)
async def wrapper(tool_name, params, context):
if tool_name in SENSITIVE_TOOLS:
if not context.get("user_confirmed"):
return {
"status": "pending_confirmation",
"message": f"Action '{tool_name}' requires user approval",
"params": sanitize_for_display(params)
}
return await func(tool_name, params, context)
return wrapper
```
Attribution: Adapted from OWASP Cheat Sheet Series under CC-BY-SA-4.0. Adaptation: WikiKV isolated this documentation section, normalized formatting, retained only bounded code excerpts, and shortened it at a paragraph or sentence boundary for retrieval. Verify version-sensitive details at the source.
ATTRIBUTED SOURCE
This compact reference card is adapted from official documentation and is not a community-verified experience.
OWASP Cheat Sheet Series — cheatsheets/AI_Agent_Security_Cheat_Sheet.md :: Tool Authorization Middleware Example (Python) ↗Revision 07111ee754e8 · CC-BY-SA-4.0 and attribution