← Back to Labs

Autonomous AI Agent Safety & Policy Controls

Trace the ReAct execution loop, indirect prompt injection attacks, tool privilege escalation, and Cedar policy enforcement

BLOCKED1. ReAct ContextSystem Prompt & SchemaClean Baseline2. External DocPDF / Web ArticleIngest Buffer3. ReAct AgentThought-Action LoopNormal ReasoningUser Intent Aligned4. Tool Invocationhttp_post_request()http://attacker-c2.net5. Cedar Policy GateLeast Privilege EnginePolicy Monitoring6. Ed25519 Audit ReceiptSig: 0x9a8f...3e21 [VERIFIED]INIT: Context Bound
STEP 1 OF 6

ReAct Agent Context Initialization

The AI agent initializes its context window with system instructions, security guidelines, user prompt, and available tool schemas (such as file reading and exfiltration API endpoints).

Arrow keys to navigate · R to reset

Tap dots to jump to any step

Read the full article →Take the quiz →