Control Packs · INP-001 · v1.0.0
Untrusted Input Handling
Validate, bound, and safely render content that people outside the system control, and keep it from reaching an interpreter, a privileged path, or another user unchecked.
Status: review · Review: not independent. This is design guidance; review status does not establish independent verification or compliance.
What this safeguard addresses
Ensure content controlled by parties outside the system has a validated shape and bounded size on entry, is encoded for its destination on the way out, and cannot by itself widen the system's authority.
- Content someone else controls is trusted by defaultContent submitted by a user, customer, partner, or automated caller is stored, rendered, or acted on without a validated shape, a size bound, or an output-encoding boundary, so it can reach an interpreter, another user's session, or a privileged code path.
Versioned applicability rule
{
"characteristic": "UNTRUSTED_INPUT",
"equals": true
}Decisions for the project owner
Leave a decision open when its value is unknown. Suggested values become confirmed only through an explicit user decision.
- Which inputs come from outside the system, and what is each allowed to contain?Content the system did not author needs a stated shape and size before it is stored, rendered, or acted on; the system must not infer those limits for you.INP-001-Q1 · scope
Requirements for the coding agent
- INP-001-R1Validate every externally controlled input against an explicit allowed shape and size, reject rather than coerce what does not conform, encode output for its destination, and ensure untrusted content cannot escalate authority or reach another tenant or user unchecked.
Tests and evidence to retain
- UNTRUSTED_INPUT_TESTExercise oversize, malformed, wrong-type, and hostile-payload inputs, and confirm rejection, safe rendering, and that no authority is gained.
- configuration_or_policy
- implementation_location
- test_result
- telemetry_definition
Passing a published example shows that example's behavior. A coding agent's implementation report remains a claim until its evidence is independently checked.
Related guidance
- SI-10 · Information Input ValidationNIST_SP_800_53_5_2_0 · partially addressesA confirmed allowed shape and size for externally controlled input is a focused form of input validation; it does not cover every information-input control in the family.
- SI-15 · Information Output FilteringNIST_SP_800_53_5_2_0 · partially addressesEncoding untrusted content for its destination supports output filtering for this path; it does not establish a complete output-filtering program.
- SC-5 · Denial-of-Service ProtectionNIST_SP_800_53_5_2_0 · informsBounding input size limits one avenue of resource exhaustion; it is not a denial-of-service protection strategy on its own.
Mappings indicate contextual relevance or partial support. They do not establish equivalence, certification, government endorsement, or complete framework implementation.
- OWASP Cheat Sheet Series — LLM Prompt Injection Prevention Cheat SheetGUIDANCE_AI_CONTENT_BOUNDARY
- National Institute of Standards and Technology — Security and Privacy Controls for Information Systems and OrganizationsGUIDANCE_NIST_SP_800_53_5_2_0