The paper presents a pre-deployment pipeline for securing multi-agent applications by scanning prompt templates, tool interfaces, and tool-invocation code for leakage-enabling patterns, then generating minimally invasive patches. The hardening methods include schema tightening, boundary sanitization, allowlist-based tool gating, and least-privilege checks. A validation stage generates adversarial prompt-injection inputs, including jailbreaks, instruction overrides, and tool-targeted manipulation, alongside benign task variants. Evaluated on five real-world agentic applications and AgentDojo, the authors report a 100% reduction in leakage against basic jailbreak and instruction-override attacks, and a 91% reduction under stress-induced manipulation.
No heat snapshots are available in the last 24 hours.