安全评审在发布前进行,覆盖核心威胁场景
在连接器发布前,Harvey的安全团队会针对一系列威胁场景开展评审,包括提示注入、写入能力滥用、凭据泄露、跨租户数据泄露及供应链风险;运行时,每次工具调用仍须通过权限与策略检查。
支持这项说法
我们如何构建Harvey的连接器库
连接器安全始于工具面向用户发布之前,并持续到智能体调用该工具时。发布前,我们的安全团队评估提示注入、写入能力被误用、凭据泄露、跨租户数据泄露及供应链风险等威胁;运行时,每次调用仍需通过相应的权限与策略检查。
原始摘录
Connector security starts before a tool reaches users and continues when the agent calls it. Before launch, our security team reviews threats such as prompt injection, misuse of write capabilities, credential compromise, cross-tenant leakage, and supply-chain risk. At runtime, each call must still pass the applicable permission and policy checks.
分享观点验证此主张