Chapter 2 of 6 · Architecture

Red teaming, prompt injection, and Defender

Runtime assurance 4 hours in a non-production POC

Chapter 2 of 6

Architecture at a glance#

A baseline attack run leads to remediation, a new immutable version, and a same-plan rerun for the risk decision.

The runner resolves the exact agent version, runs the approved Foundry taxonomy, and writes a payload-free aggregate to the approved security record store outside this repository. The comparison script checks both aggregates and reads a separate SOC-delivery record.

Foundry is authoritative for red-team detail. Defender and the SOC system are authoritative for security delivery. Existing tool and backend controls remain the boundary for prohibited writes.

Design choices and tradeoffs#

DecisionChosen approachBenefitsCosts and limitations
ComparisonSame plan, two immutable versionsIsolates the remediation changeGenerative results still need human review
Tool safetyRead-only tool; writes independently deniedModel failure cannot produce a writeDoes not test real writes
Route checkAuthorized event or route-health resultAvoids manufacturing an attackProves delivery, not remediation quality

Architecture guidance#

Session 10

Red teaming, prompt injection, and Defender slide deck