Amo.ng curated workflow

Investigate an AI Agent Security Incident

Reconstruct an AI agent incident, trace delegated authority and sensitive context, conditionally investigate memory or RAG authorization, and prepare evidence-based containment and recovery gates.

Workflow ID
AMO-W-000012
Steps
5
Published
Download Markdown

Copy workflow includes every step and the full linked Prompt content. Use with AI copies a shorter guide with Prompt links; neither action runs the Workflow.

Outcome

An incident decision package containing the first supported coordination divergence, principal and delegation chain, sensitive-context lineage, applicable memory or retrieval findings, affected scope, containment actions, recovery conditions, and regression evidence requirements.

Before you begin

Have all or some of the following available before you start. The more relevant context you can provide, the stronger the workflow output will be.

  • Incident symptoms, impact, time window, and affected environments
  • Agent roles, handoff contracts, tools, identities, permissions, and shared-state design
  • Sanitized traces, logs, messages, state or memory records, retrieval evidence, and incident tickets
  • Expected authorization, tenant, purpose, region, retention, and data-handling boundaries
  • Known changes, containment already performed, operational constraints, and accountable owners

Ordered sequence

Workflow steps

Complete the steps in order. For each step, provide the listed context, carry its result into the next step, and pause wherever a review note is shown.

  1. Step 1 Reconstruct the coordination failure

    Use the incident evidence to build the chronology, identify the first coordination divergence, compare plausible mechanisms, and draft the smallest testable correction to the failed handoff or shared-state contract.

    Prompt: Multi-Agent Coordination Failure Reconstruction

    Input for this step

    Supply the incident scope, agent roles, expected handoffs, messages or traces, shared-state evidence, observed impact, and authorized investigation boundary.

    Carry forward

    Carry the evidence inventory, chronology, first-divergence finding, competing hypotheses, affected agents or state, evidence gaps, and discriminating tests into the authority review.

    Review note

    The incident owner and service owner confirm the investigation boundary and whether the first-divergence finding is sufficiently supported to guide the next reviews.

    Open prompt
  2. Step 2 Trace principal identity and delegated authority

    Reconstruct which principal acted, which identity or credential was presented, how authority was delegated, and where authorization context was lost, stale, broadened, or misapplied.

    Prompt: Agent Identity and Delegated Authorization Failure Review

    Input for this step

    Use the coordination chronology plus identity claims, tokens or credential metadata, authorization policies, tool-call records, downstream audit logs, revocation evidence, and ownership rules.

    Carry forward

    Carry the principal chain, delegation defects, affected actions, evidence confidence, repair requirements, and authorization regression gates into the context-lineage review.

    Review note

    The security reviewer and relevant system owner verify the principal-chain evidence and decide whether any credential, session, connector, or workflow requires containment.

    Open prompt
  3. Step 3 Trace sensitive-context propagation

    Map sensitive context across agent handoffs, tools, retrieval, memory, logs, caches, and shared workspaces. Separate confirmed propagation from plausible exposure and identify purpose, tenant, retention, or minimization failures.

    Prompt: Sensitive Context Propagation and Cross-Agent Contamination Audit

    Input for this step

    Supply the prior chronology and principal chain with representative payloads, handoff records, context or memory configuration, data classifications, tenant and purpose rules, logging behavior, and retention evidence.

    Carry forward

    Carry the lineage map, contamination findings, affected data classes, propagation mechanisms, deletion or minimization needs, and unresolved exposure questions into conditional memory and retrieval investigations.

    Review note

    The data owner, privacy reviewer, and security reviewer confirm impact classification and authorize any deletion, notification, isolation, or retention decision.

    Open prompt
  4. Step 4 Investigate persistent memory when applicable

    Run this step only when persistent memory could have introduced, retained, or propagated the failure. Otherwise record Not applicable and the evidence supporting that boundary. When applicable, reconstruct memory provenance, poisoning hypotheses, affected decisions, quarantine posture, and recovery gate.

    Prompt: Agent Memory Integrity and Poisoning Investigation

    Input for this step

    Provide the context-lineage findings, memory stores and schemas, write and retrieval paths, memory records, audit history, retention rules, suspicious symptoms, and recovery authority boundaries.

    Carry forward

    Carry the memory provenance ledger, supported poisoning or integrity conclusion, affected decisions, quarantine state, recovery prerequisites, and remaining uncertainty to the final authorization-boundary review.

    Review note

    The memory service owner and data owner authorize quarantine, correction, deletion, re-attribution, or restoration; absence of memory evidence must not be treated as proof of integrity.

    Open prompt
  5. Step 5 Investigate RAG authorization exposure when applicable

    Run this step when retrieval, embeddings, citations, caches, or corpus authorization could have exposed data across identity, tenant, purpose, region, or document boundaries. Otherwise record Not applicable and why. Reconcile its findings with the principal and context-lineage evidence.

    Prompt: RAG Access-Control Leakage Investigation

    Input for this step

    Provide query and response traces, retrieved document or citation evidence, document ACLs, identity and tenant context, ingestion and cache records, authorization policies, and the prior incident findings.

    Carry forward

    Produce the final incident package: authorization map, affected scope, containment decision, memory or RAG conditions, repair priorities, regression matrix, recovery gate, owners, and evidence still required.

    Review note

    The incident owner, security reviewer, data owner, and release owner make the contain, recover, restrict, or continue-investigation decision.

    Open prompt

Completion criteria

The workflow is complete when:

  • The earliest supported coordination divergence and principal chain are traceable to supplied evidence.
  • Sensitive-context exposure is classified as confirmed, likely, possible, unsupported, or not assessable.
  • Memory and RAG investigations are completed when applicable or explicitly marked Not applicable with a reason.
  • Containment, recovery, and regression conditions identify evidence, owners, stop conditions, and unresolved uncertainty.
  • No action, test, inspection, approval, or recovery is represented as completed without corresponding evidence.
Browse Workflows

Was this useful?