Improper Output Handling
- Output / Actuation
Model-generated content is passed downstream — into a shell, a query, a browser, a terminal, a deployment pipeline, another agent — without validation or encoding, so the model's text becomes an execution path.
What it is
Improper output handling is a gap between what a model generates and what a downstream system does with it: insufficient validation, sanitization, or encoding before the output reaches a shell, a database, a browser, a terminal, or another agent turns generated text into an execution path. Because the output is shaped by the prompt, an attacker who controls the input indirectly controls what gets executed — the model is an untrusted intermediary, not a client whose text can be trusted by default.
The boundary to its neighbors is sharp: this entry concerns the unsafe use of output, Misinformation (LLM07) output that is wrong, Prompt Injection (LLM01) the validation of input. It fell from fifth to tenth in 2026 while growing in scope — it now spans the insecure code assistants generate at scale and ship without review, control characters a terminal or log viewer interprets, and chat interfaces that fetch whatever a Markdown image in the output points at.
The risk compounds in an agentic system, where one agent's output routinely becomes another agent's input. A downstream agent that trusts a peer's generated text the way it trusts its own reasoning inherits every unvalidated payload the upstream agent produced, with no record of where it came from.
Kinds
- Code and command injection
- Generated text reaches a shell or a function like exec or eval, or generated code is compiled and deployed without review.
- Markup and script injection
- Generated JavaScript or Markdown is rendered without sanitization, producing cross-site scripting — or an auto-rendered image URL exfiltrates conversation data.
- Query and path injection
- A generated SQL fragment or file path is used without parameterization or sanitization, escaping its intended scope.
- Control-character injection
- ANSI escape sequences in output written to a terminal, log viewer, or IDE enable visual spoofing or clipboard hijacking.
Attack scenarios
An agent's generated SQL fragment is concatenated directly into a live query, and an injected character lets the query read outside the caller's own records.
Unvalidated privileged extension
A general-purpose model passes its response straight to a privileged extension without output validation, and the extension acts on content it should have treated as untrusted.
Summarizer exfiltration
A webpage-summarizer agent processes a hidden instruction in the page, encodes sensitive conversation content, and sends it to an attacker-controlled server.
Destructive generated SQL
A chat feature lets a user request a database query in natural language; the model's SQL runs without review, and a destructive request deletes production tables.
Auto-deployed generated code
An application compiles and deploys model-generated code without review or security testing, and the insecure code reaches production and is exploited.
Mitigations
- Treat model output as untrusted input
- Apply zero-trust validation to every model response before it reaches a backend function, matching Output Validation / Schema Enforcement.
- Encode output for its destination
- Encode for the sink the output reaches, use parameterized queries, strip control characters before writing to terminals and logs, and disable auto-fetching of images and link previews.
- Sandbox and review what can execute
- Run generated code or commands inside Sandbox Execution, isolated from the host, and never deploy generated code without review and security testing.
- Log and monitor outbound patterns
- The Audit Trail's record of what left the system turns a single exploit attempt into a detectable pattern.