Toxic flow analysis traces combinations of private data, untrusted input, and external action. It exposes prompt-injection, tool-poisoning, and exfiltration paths.
Use this profile to understand the building block briefly, place it in the model, and open related building blocks.
Executable approach: can be applied and produces an outcome.
What organizes, connects, or makes decisions possible.
Toxic flow analysis examines how harmful or unreliable information moves through a workflow or AI system and can distort decisions.
The approach combines threat modeling, data-flow analysis, and security work on generative AI systems. Thoughtworks introduced Toxic Flow Analysis as a technique for exposing risky data and instruction paths in AI-assisted workflows.
Draw sources, processing steps, and outputs as a chain. At each transition, ask whether manipulated, false, or sensitive input is forwarded and which control can stop or flag the flow.
An input may be trusted, manipulated, or unclear.
Risks can spread across tools and agents.
Validation, isolation, and approval limit harmful impact.
The analysis finds security risks at transitions before they reach users or systems; it does not replace domain review of data and models.
Where this building block is located in the topic model.
No structure path available.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.