skip to content

In a chain of components, what property makes one hop the right place for an attacker to launder text through?

level: middleimportance: should knowfreq 44%

answer

  1. the attacker picks a hop, not a payload
  2. does this component emit prose at all
  3. behind the boundary, so nothing runs there
  4. the value is the reader's capabilities
  5. restatement is the toll it must pay

basics

~20 s

The hop worth laundering through is the one whose output the next component reads as free text rather than a typed record, sitting behind the single arrival check, and read by a component with capabilities the emitter lacks.

solid answer

~50 s

Three properties have to line up, and an attacker picks the hop where they do. First, the emitting component's output must contain an unconstrained member — prose, not an enumeration — because that is the only part of a record that carries arbitrary wording forward. Second, the hop must sit *behind* the boundary check, so its output is internal by construction and no second screen is expected there. Third, the reading component must be able to do something the emitting one cannot; laundering into a component with no capabilities buys nothing. A hop that emits only typed members carries nothing across; a hop whose output goes to a human rather than into another model's context has a reader, not a parser, at the far end. The attacker also pays: their wording must survive whatever restatement the emitting component performs, and they usually cannot see the record to check.

go deeper

for a junior

Know that components hand each other records, that most members of a record are typed and closed, and that the free-text member is the one arbitrary wording can travel in.

for a middle

Be able to state hop selection as three mechanical properties — an unconstrained output member, a position behind the boundary check, and a reader with capabilities — and to say which pipelines lack each one.

for a senior

Demonstrate that you would cost the construction honestly: survival through restatement, blindness to the record, and two independent release cadences all make it degrade rather than hold. Say what evidence would tell you it still works.

for a principal

Frame this as a property of the system's shape rather than of any one component, and be ready to say what a design that emits prose between models has committed to, long before any specific finding lands.

## The question an attacker is actually asking A pipeline is a series of hops. The attacker does not get to choose where their content enters — that is fixed by whatever channel the product exposes — but they do get to choose which hop they are *aiming* at, and that choice determines whether anything happens at all. The selection criteria are mechanical, and being able to state them is what separates someone who can name the attack class from someone who could construct one. ## Property one: the output has an unconstrained member Components hand each other records. Most of a record is typed: enumerations, identifiers, numbers, timestamps. Those members are closed — their legal values were fixed when the schema was written, so an attacker's prose cannot appear inside them. What matters is whether the record has a member whose values *could not* be enumerated in advance: a `notes`, a `rationale`, a `summary`. That member exists in most real handoffs precisely because some part of a finding is irreducibly prose, and it is the only member that carries wording across the hop. So the first filter is: does this component emit prose at all? A component that returns a decision and a code is a dead end for this construction. ## Property two: the hop is downstream of where trust was defined Every pipeline has a place where *untrusted* was decided — a check on arriving content at the boundary, run once, on the artefact as it came in. Its scope is the arrival channel. Everything past that point is internal *by construction*, which is a topology statement, not a property of any message. That is what makes a hop behind the boundary attractive: not that a control was defeated, but that no control is expected there, and the record arriving at the next component wears an internal label that reflects who emitted it rather than where the words came from. Notice the shape of the reasoning. The attacker does not need to get past the check twice. They need their content to be *re-emitted* on the far side of it by something the pipeline already trusts. ## Property three: the reader is worth reaching Laundering into a component that can only produce text is worth much less than laundering into one that can act — one that writes to a shared store, calls out, files, assigns, or spends. The value of the hop is the capability set of the *reader*, not of the writer. This is why chains that run from a reading component into an acting one are the interesting ones, and why an attacker profiling a system is mapping which component ends up with the capabilities. ## What the construction costs It is worth being honest that this is not cheap: - **Survival through restatement.** The emitting component rarely copies; it summarises, classifies or extracts. The attacker's content has to be shaped so that its directive character is what a restatement preserves. That is a property they select for, and it can simply fail. - **Blindness.** The attacker usually cannot see the handoff record. They are writing for a transformation they cannot observe and iterating on whatever downstream behaviour is visible to them, which may be nothing. - **Two release cadences.** When the emitting and reading components belong to different organisations, either side can change its serialisation, its prompt or its model without notice, and the construction dies quietly. ## Where the property stops holding - The emitting component's output is fully typed, so there is no prose to ride. - The record's prose member is rendered for a human and never re-enters another model's context — the far end has a reader, not a parser. - The reading component holds no capability the emitting one lacked, so nothing is gained by the hop. - The prose member is short enough, or the restatement aggressive enough, that directive-shaped spans do not survive it — this is a probabilistic property, not a guarantee, which is why it degrades rather than blocks. ## How to answer this in an interview Do not list attack families. State the three properties as a selection procedure, then say which one you would test first on a system you had just been handed — usually *does any hop emit prose into another model's context*, because if the answer is no the rest does not matter.

  • You are handed an unfamiliar pipeline. Which of the three properties do you test first, and why?
    Whether any hop emits prose into another model's context. It is the cheapest to determine from the schemas alone, and if no hop does, the whole construction is unavailable no matter how the capabilities are arranged. Capability mapping is more expensive to establish and only matters once you know there is a carrier.
  • Does it matter whether the emitting component copies its input or summarises it?
    It changes the cost, not the existence of the path. Copying carries wording through unchanged; summarising imposes a toll, since the content only survives if its directive character is what a restatement preserves. Summarising also makes the outcome probabilistic, which is why the same construction can work in one attempt and not the next.
  • Why is a hop whose prose output is shown to a person a much weaker choice?
    Because the far end is a reader rather than a parser. A person is not enumerating a context window and acting on the most instruction-shaped span in it, and prose that looks like an injected directive is conspicuous to a human in a way it is not to a model. The hop still transmits the words, but nothing downstream converts them into an action.

saying these in an interview costs you the question

  • Talks about payload wording instead of hop selection
  • Assumes any internal message is an equally good carrier
  • Ignores the reading component's capability set
  • Presents the construction as free and reliable
  • Thinks a typed schema with one prose member is fully typed

context