| ▲ | gostsamo 2 hours ago | |||||||
you can restrict the email send tool to have to/cc/bcc emails hardcoded in a list and an agent independent channel should be the one to add items to it. basically the same for other tools. You cannot rewire the llm, but you can enumerate and restrict the boundaries it works through. exfiltrating info through get requests won't be 100% stopped, but will be hampered. | ||||||||
| ▲ | botusaurus 2 hours ago | parent [-] | |||||||
parent was talking about a different problem. to use your framing, how you ensure that in the email sent to the proper to/cc/bcc as you said there is no confidential information from another email that shouldnt be sent/forwarded to these to/cc/bcc | ||||||||
| ||||||||