Agent Application DevelopmentAccount
Knowledge catalogChoose core direction and segmented content
Practice 46AdvancedSystem designAbout 15 minutes

Corresponding knowledge: Approval targets and execution-time authorization

Agent can call the writing tool. How to prevent parameters from being modified after exceeding authority and approval?

Implement permission checks at the tool execution boundary, bind approval to immutable parameters and resource versions, and reject prompt injection to expand authorization.

Permission isolationManual approvalMCPPrompt Injection

Knowledge content check2026-10-03 · Check the source of the original question2026-10-02

Knowledge unit directory

LEARN · PRACTICE · REFLECT

Knowledge exercises·Independent answers

My notes and review ↗

Principles and Solutions have been collapsed. Explain the core mechanism, boundaries and verification methods in your own words, and then compare them.

Answers and personal notes

Each modified commit will be kept as an independent history. Your level of mastery is up to you to evaluate yourself against the standards.

Explain in your own words first

The core principles, analysis, Q&A and migration cases have been closed. When you are ready, unfold it and compare it with the content to find any omissions.

Hands-on verificationComplete on demand · Suggestions15 minutes

Deducing how the execution gateway should handle changes to recipients after approval.

Expand acceptance requirements and checkpoints
  • Old approvals cannot cover new recipients
  • Server-side verification and trustworthy approval
  • Repeated callbacks are not executed repeatedly

Key inspections

  • User identity, tenant scope and resource permissions can be placed on the server side instead of relying on model parameters.
  • Can handle parameter changes and resource changes between approval and execution.
  • Understand the different boundaries of MCP authorization, business authorization and manual approval.