“prompt injection” in 2022. The lethal trifecta Give an agent all three, and anyone who can put text in front of it can steal your data. The model can't reliably tell your instructions from theirs. simonwillison.net/2025/Jun/16/the-lethal-t rifecta
second LLM to judge each tool call. • It can't follow data across calls • It doesn't see tool outputs • It can be prompt-injected too Best reported judge accuracy: 99.3% · openappa.com
the words. Deterministic Outside the loop Doesn't break agents A pure function of the event log. No Checks every tool call before it runs. Every block comes with a remedy second model to fool. Fails closed. plan, not a dead end. “You cannot prompt-inject an algebra.” · Rust core · MIT licensed · openappa.com
with the OpenAPPA ADK plugin, plus the runtime chart. • Two env vars per agent to opt in • Python and Go ADK runtimes • Runtime unreachable: every call fails closed
The agent stops and reports it. The work still got done Full incident summary, including "rotate the exposed key". Audit trail appa-runtime logs every block, release and ruling. GitHub: no CREATED.