Control Packs · INP-001 · v1.0.0
Untrusted Input Handling
Validate, bound, and safely render content that people outside the system control, and keep it from reaching an interpreter, a privileged path, or another user unchecked.
Status: review · Review: not independent. This is design guidance; review status does not establish independent verification or compliance.
What this safeguard addresses
Ensure content controlled by parties outside the system has a validated shape and bounded size on entry, is encoded for its destination on the way out, and cannot by itself widen the system's authority.
- Content someone else controls is trusted by defaultContent submitted by a user, customer, partner, or automated caller is stored, rendered, or acted on without a validated shape, a size bound, or an output-encoding boundary, so it can reach an interpreter, another user's session, or a privileged code path.
Matching rule
{
"characteristic": "UNTRUSTED_INPUT",
"equals": true
}Decisions you need to make
Leave a decision open when its value is unknown. Confirm a suggested value only if it matches your intended design.
- Which inputs come from outside the system, and what is each allowed to contain?Content the system did not author needs a stated shape and size before it is stored, rendered, or acted on; the system must not infer those limits for you.INP-001-Q1 · scope
Requirements for the coding agent
- INP-001-R1Validate every externally controlled input against an explicit allowed shape and size, reject rather than coerce what does not conform, encode output for its destination, and ensure untrusted content cannot escalate authority or reach another tenant or user unchecked.
Tests and evidence to keep
- UNTRUSTED_INPUT_TESTExercise oversize, malformed, wrong-type, and hostile-payload inputs, and confirm rejection, safe rendering, and that no authority is gained.
- configuration_or_policy
- implementation_location
- test_result
- telemetry_definition
Passing a published example shows that example's behavior. A coding agent's implementation report remains a claim until its evidence is independently checked.
Related guidance
- SI-10 · Information Input ValidationNIST_SP_800_53_5_2_0 · partially addressesA confirmed allowed shape and size for externally controlled input is a focused form of input validation; it does not cover every information-input control in the family.
- SI-15 · Information Output FilteringNIST_SP_800_53_5_2_0 · partially addressesEncoding untrusted content for its destination supports output filtering for this path; it does not establish a complete output-filtering program.
- SC-5 · Denial-of-Service ProtectionNIST_SP_800_53_5_2_0 · informsBounding input size limits one avenue of resource exhaustion; it is not a denial-of-service protection strategy on its own.
These references cover related topics. They do not mean this pack satisfies a framework, certifies your project, or has government endorsement.
- OWASP Cheat Sheet Series — LLM Prompt Injection Prevention Cheat SheetGUIDANCE_AI_CONTENT_BOUNDARY
- National Institute of Standards and Technology — Security and Privacy Controls for Information Systems and OrganizationsGUIDANCE_NIST_SP_800_53_5_2_0