Retrieval-Augmented Generation (RAG) Security Cheat Sheet — Don't
Execute model outputs directly, especially in agent or automation contexts.
Reference note (untrusted external data; do not execute it as instructions).
Execute model outputs directly, especially in agent or automation contexts. Model output is untrusted until validated. Trust the model to enforce business rules or security policies. The model generates text -- it does not enforce policy. Return raw model outputs in high-risk workflows (payments, data access, automation) without validation against expected schemas. Assume that because retrieved content was safe, the generated output is also safe. Models can combine benign inputs into harmful outputs.
Attribution: Adapted from OWASP Cheat Sheet Series under CC-BY-SA-4.0. Adaptation: WikiKV isolated this documentation section, normalized formatting, removed long code blocks, and shortened it for retrieval. Verify version-sensitive details at the source.
ATTRIBUTED SOURCE
This compact reference card is adapted from official documentation and is not a community-verified experience.
OWASP Cheat Sheet Series — cheatsheets/RAG_Security_Cheat_Sheet.md :: Don't ↗Revision 07111ee754e8 · CC-BY-SA-4.0