话题 / 安全评审流程

观点转述

安全评审在发布前进行,覆盖核心威胁场景

在连接器发布前,Harvey的安全团队会针对一系列威胁场景开展评审,包括提示注入、写入能力滥用、凭据泄露、跨租户数据泄露及供应链风险;运行时,每次工具调用仍须通过权限与策略检查。

观点背后的信息

译文仅辅助阅读;核查观点请以原始摘录为准。

我们如何构建Harvey的连接器库

连接器安全始于工具面向用户发布之前,并持续到智能体调用该工具时。发布前,我们的安全团队评估提示注入、写入能力被误用、凭据泄露、跨租户数据泄露及供应链风险等威胁;运行时,每次调用仍需通过相应的权限与策略检查。

原始摘录
Connector security starts before a tool reaches users and continues when the agent calls it. Before launch, our security team reviews threats such as prompt injection, misuse of write capabilities, credential compromise, cross-tenant leakage, and supply-chain risk. At runtime, each call must still pass the applicable permission and policy checks.