Business Expert Claude

Sensitive Context Propagation and Cross-Agent Contamination Audit

Trace sensitive context across agent handoffs, memory, retrieval, tools, logs, and shared workspaces to identify unauthorized propagation and contamination risk.

Use in AI

Choose an AI tool to copy the current Prompt with a short usage note. Nothing is sent to that tool.

Browse more prompts
Best forSecurity review
ToolClaude
DifficultyExpert
Full Prompt
Conduct an evidence-based audit of sensitive context propagation across the specified agent workflow. Trace actual context movement through handoffs, memory, retrieval, tools, logs, outputs, and shared workspaces. Do not produce a generic sensitive-data checklist. Separate observed evidence from inference, expose missing information, and preserve uncertainty.

Context to provide:
- System or workflow under review: [System or workflow under review]
- Authorized purposes and tenant boundaries: [Authorized purposes and tenant boundaries]
- Sensitive context categories: [Sensitive context categories]
- Evidence package: [Evidence package]
- Known incidents or concerns: [Known incidents or concerns]
- Accountable owners: [Accountable owners]
- Review date range: [Review date range]

Evidence rules:
- Use only the evidence provided in [Evidence package] and clearly identified user-supplied context.
- Do not claim that a source, system, log, tool, workspace, approval, command, or deletion was inspected or completed unless evidence is present.
- Label each material statement as one of: Observed, Inferred, Not evidenced, or Requires owner confirmation.
- Distinguish sensitive context from ordinary workflow context.
- Distinguish authorized propagation from unauthorized propagation, excessive retention, purpose drift, and cross-tenant or cross-task contamination.
- If evidence is incomplete, state the missing artifact and why it matters.

Audit scope:
Trace sensitive context across these surfaces where evidence exists:
1. User inputs, uploaded files, tickets, records, conversations, or task instructions.
2. Agent-to-agent handoffs, delegation messages, intermediate reasoning summaries, or task state objects.
3. Short-term memory, long-term memory, vector stores, retrieval indexes, embeddings, caches, and session stores.
4. Tool calls, API payloads, browser sessions, database queries, SaaS integrations, webhooks, automations, and background jobs.
5. Logs, traces, analytics events, evaluation datasets, transcripts, error reports, monitoring records, and support workspaces.
6. Shared folders, project workspaces, collaboration tools, exported artifacts, generated documents, and downstream notifications.
7. Human review queues, escalation paths, approval records, and operator notes.

Required deliverable:

1. Audit Boundary and Evidence Inventory
Create a concise table with:
- Evidence item
- Source or owner if known
- Date range covered
- Context surfaces covered
- Reliability limits
- Material gaps

2. Context Lineage Map
Create a lineage table that traces each sensitive context category through the workflow:
- Context item or category
- Origin
- Initial authorized purpose
- Receiving agent, service, tool, memory store, log, workspace, or person
- Transfer mechanism
- Transformation or summarization performed
- Retention location and retention duration if evidenced
- Tenant, customer, project, task, or workspace boundary crossed
- Evidence reference
- Status: authorized, questionable, unauthorized, excessive, contaminated, or not evidenced

Then provide a short narrative explaining the highest-risk propagation paths. Do not infer a path merely because it is technically possible; identify it as a hypothesis if not evidenced.

3. Sensitivity and Purpose Register
Create a register with:
- Sensitive context category
- Sensitivity rationale
- Data subject, tenant, customer, project, or task boundary affected
- Authorized purpose from [Authorized purposes and tenant boundaries]
- Actual observed use
- Purpose alignment: aligned, narrowed, expanded, drifted, unrelated, or not evidenced
- Minimum context needed for the task
- Excess context observed
- Owner accountable for purpose decision from [Accountable owners], or owner not identified

4. Cross-Agent and Cross-Boundary Contamination Findings
For each finding, include:
- Finding title
- Evidence basis
- Contamination type: cross-agent, cross-tenant, cross-task, cross-customer, cross-project, memory reuse, retrieval bleed, logging exposure, tool propagation, workspace exposure, or purpose drift
- Affected context
- Affected boundary
- How the propagation occurred or is suspected to occur
- Impact on confidentiality, integrity, compliance, customer trust, operational safety, or decision quality
- Likelihood rating: evidenced, plausible, weakly supported, or unknown
- Severity rating: critical, high, medium, low, or informational
- Confidence level and reason
- Missing evidence that would change the rating

5. Minimization and Containment Controls
Propose controls tied to the observed lineage, not generic policy slogans. For each control, include:
- Propagation point addressed
- Control objective
- Specific change to inputs, prompts, handoff schema, memory policy, retrieval filtering, tool payloads, logging, access control, workspace permissions, retention, or operator procedure
- Expected reduction in sensitive context exposure
- Owner responsible for implementation
- Verification method
- Residual risk

Prioritize smallest effective controls that reduce propagation without breaking the authorized workflow. Avoid broad rewrites unless the evidence shows the workflow design itself is unsafe.

6. Deletion, Quarantine, and Revalidation Plan
Create an action plan with:
- Artifact or location requiring deletion, quarantine, redaction, re-indexing, access review, or retention change
- Reason action is needed
- Required owner approval: data owner, security reviewer, legal/privacy owner, product owner, platform owner, or customer account owner as appropriate
- Preconditions before action
- Execution evidence needed after action
- Revalidation test or sampling method
- Rollback or exception handling if deletion would impair legal hold, auditability, customer support, or service reliability

Do not state that deletion, quarantine, redaction, or re-indexing has been completed. State only the plan and the evidence needed to verify completion.

7. Open Questions and Owner Decisions
List unresolved questions that materially affect risk or remediation. For each, identify:
- Question
- Why it matters
- Evidence needed
- Accountable owner from [Accountable owners], or owner not identified
- Decision deadline if inferable from [Known incidents or concerns]

8. Completion Check
End with a completion check stating whether the audit is ready for owner review. Include:
- Whether every sensitive context category in [Sensitive context categories] was traced or marked not evidenced
- Whether every material propagation path has an evidence reference or uncertainty label
- Whether contamination findings are tied to actual lineage evidence
- Whether minimization controls map to specific propagation points
- Whether deletion and revalidation actions identify accountable owners and verification evidence
- Remaining blockers before security reviewer, data owner, product owner, or platform owner decision

Variables to Replace

Replace each listed value in the Prompt with information relevant to your task.

  • System or workflow under review
  • Authorized purposes and tenant boundaries
  • Sensitive context categories
  • Evidence package
  • Known incidents or concerns
  • Accountable owners
  • Review date range

How to Use This Prompt

Use in Claude. Paste or upload the workflow description, agent handoff records, memory or retrieval configuration, tool/API payload examples, logs or traces, workspace exports, access boundaries, retention rules, and any incident notes. Replace every bracketed placeholder, then run the prompt. Have the security reviewer, data owner, product owner, and platform owner verify the lineage evidence, owner assignments, and deletion or revalidation plan before acting on remediation.

Example Use Case

A product owner and security reviewer are preparing to launch a multi-agent customer support workflow. They use this prompt with handoff transcripts, vector-store configuration, tool payload samples, and shared workspace logs to identify that summarized customer account details are being retained in a reusable memory store and surfaced in unrelated support tasks. The output gives them a lineage map, contamination findings, targeted minimization controls, and a deletion/revalidation plan for owner review.

Was this useful?

Build stronger AI systems

Use Amo.ng prompts as reusable building blocks, then go deeper with RichlyAI.

Related Prompts

Browse all
Business Expert Claude

AI Incident Response Tabletop Exercise

Design and facilitate a realistic AI incident tabletop with controlled injects, decision evidence, escalation, communications, recovery gates, and accountable follow-up.

Updated Aug 11, 2026

View prompt Verified ✓ 96 views · 3 copies