Model-generated content is passed downstream — into a shell, a database query, a browser, another agent — without adequate validation or sanitisation, so the model's text becomes an execution path. In a multi-agent system: An agent's generated SQL fragment is concatenated directly into a live query, and an injected character lets the query read outside the c…
Use this profile to understand the building block briefly, place it in the model, and switch to the 360° assessment when needed.
Theoretical construct: explains a term, principle, or mental model.
What organizes, connects, or makes decisions possible.
Improper output handling is the unchecked passing of model or agent output to downstream systems.
The risk comes from classic application security, where unvalidated inputs and outputs cause injection and execution failures; OWASP explicitly describes this transfer for LLM applications.
An output is first treated as untrusted data, validated, and constrained to an allowed structure and effect. Only then may it reach SQL, shell commands, browser actions, or further agent flows.
Model-generated content is passed downstream — into a shell, a database query, a browser, another agent — without adequate validation or sanitisation, so the model's text becomes an execution path.
In a multi-agent system: An agent's generated SQL fragment is concatenated directly into a live query, and an injected character lets the query read outside the caller's own records.
Primary mitigation: Validate every model-generated payload with Output Validation / Schema Enforcement before use, and run any generated code inside Sandbox Execution.
The pattern matters wherever generated text can trigger actions. Schema validation, output encoding, command allowlists, and human approval reduce risk; plausibility checks alone are rarely sufficient.
Where this building block is located in the topic model.
No structure path available.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.