GAISSF / D3 / D3-CTL-03

Agentic Prompt Chaining Detection

Objective

Detect distributed attacks leveraging multiple agents/turns to bypass controls.

Control / requirement

Cross-session behavioural correlation + chain pattern detection + anomaly scoring.

Business impact

Prompt chaining evades single-turn guardrails. Estimated exposure: $1M–$5M.

Validation approach

Test ID: D3-CTL-03-VTS-001 Test Type: Automated Test Design: Execute multi-step benign-then-malicious prompt sequence across 3+ agents; measure detection. Execution Steps: 1. Load GAISSF™ chaining benchmark 2. Route through multi-agent test topology 3. Monitor cross-agent state transitions 4. Calculate detection rate Pass Criteria: chain_detection_rate >= 95%; false_positive_rate < 5%; correlation_latency < 2s Independent Verification: Auditor runs multi-agent chaining test suite.

Expected evidence

Not separately specified in the available source.

Mapping and source

Not separately specified in the available source.

Implementation guidance

Translate the requirement into system-specific procedures, responsible roles, technical configurations and review conditions. Retain evidence showing both design and operating performance. Where the source provides no separate implementation instruction, do not infer that a single technical mechanism is sufficient.

Assessment considerations

  • Confirm scope and applicability.
  • Inspect control design and responsible ownership.
  • Test representative operation and adverse conditions where appropriate.
  • Evaluate evidence provenance, completeness and contradictory evidence.
  • Record limitations and notably absent outcomes.