Improper Output Handling

Attack surface
  • Output / Actuation

Model-generated content is passed downstream — into a shell, a query, a browser, a terminal, a deployment pipeline, another agent — without validation or encoding, so the model's text becomes an execution path.

What it is

Improper output handling is a gap between what a model generates and what a downstream system does with it: insufficient validation, sanitization, or encoding before the output reaches a shell, a database, a browser, a terminal, or another agent turns generated text into an execution path. Because the output is shaped by the prompt, an attacker who controls the input indirectly controls what gets executed — the model is an untrusted intermediary, not a client whose text can be trusted by default.

The boundary to its neighbors is sharp: this entry concerns the unsafe use of output, Misinformation (LLM07) output that is wrong, Prompt Injection (LLM01) the validation of input. It fell from fifth to tenth in 2026 while growing in scope — it now spans the insecure code assistants generate at scale and ship without review, control characters a terminal or log viewer interprets, and chat interfaces that fetch whatever a Markdown image in the output points at.

The risk compounds in an agentic system, where one agent's output routinely becomes another agent's input. A downstream agent that trusts a peer's generated text the way it trusts its own reasoning inherits every unvalidated payload the upstream agent produced, with no record of where it came from.

Kinds

Code and command injection
Generated text reaches a shell or a function like exec or eval, or generated code is compiled and deployed without review.
Markup and script injection
Generated JavaScript or Markdown is rendered without sanitization, producing cross-site scripting — or an auto-rendered image URL exfiltrates conversation data.
Query and path injection
A generated SQL fragment or file path is used without parameterization or sanitization, escaping its intended scope.
Control-character injection
ANSI escape sequences in output written to a terminal, log viewer, or IDE enable visual spoofing or clipboard hijacking.

Attack scenarios

In a multi-agent system

An agent's generated SQL fragment is concatenated directly into a live query, and an injected character lets the query read outside the caller's own records.

Unvalidated privileged extension

A general-purpose model passes its response straight to a privileged extension without output validation, and the extension acts on content it should have treated as untrusted.

Summarizer exfiltration

A webpage-summarizer agent processes a hidden instruction in the page, encodes sensitive conversation content, and sends it to an attacker-controlled server.

Destructive generated SQL

A chat feature lets a user request a database query in natural language; the model's SQL runs without review, and a destructive request deletes production tables.

Auto-deployed generated code

An application compiles and deploys model-generated code without review or security testing, and the insecure code reaches production and is exploited.

Mitigations

Treat model output as untrusted input
Apply zero-trust validation to every model response before it reaches a backend function, matching Output Validation / Schema Enforcement.
Encode output for its destination
Encode for the sink the output reaches, use parameterized queries, strip control characters before writing to terminals and logs, and disable auto-fetching of images and link previews.
Sandbox and review what can execute
Run generated code or commands inside Sandbox Execution, isolated from the host, and never deploy generated code without review and security testing.
Log and monitor outbound patterns
The Audit Trail's record of what left the system turns a single exploit attempt into a detectable pattern.

Security

Where to next

Search

Search patterns, frameworks, and pages.