AI Agent 資安與治理實戰(中英對照版) / AI Agent Security and Governance in Practice (Bilingual Edition)
從 Prompt Injection、Skill 供應鏈到權限控管、沙盒隔離與稽核 / From Prompt Injection and Skill Supply Chains to Access Control, Sandboxing, and Auditing

AI Agent 資安與治理實戰(中英對照版) / AI Agent Security and Governance in Practice (Bilingual Edition)
從 Prompt Injection、Skill 供應鏈到權限控管、沙盒隔離與稽核 / From Prompt Injection and Skill Supply Chains to Access Control, Sandboxing, and Auditing
當 AI Agent 不只回答問題,還能讀取檔案、呼叫工具、修改系統與對外傳送資料,安全治理就不能只靠一句「請勿洩漏機密」。本書以資產、風險、控制與驗收四步驟,拆解 Prompt Injection、MCP 與 Skill 供應鏈、最小權限、憑證保護、沙盒隔離、人工核准、記憶污染、稽核追蹤及紅隊測試。 全書採繁體中文與英文逐段對照,並提供六個企業標準情境、可直接使用的治理範本、60 項上線檢查表與實作實驗,協助開發、資安、維運及管理團隊把抽象政策落實為可驗證的工作流程。 When an AI agent can read files, call tools, modify systems, and transmit data—not merely answer questions—security governance cannot rely on a single instruction such as “do not disclose secrets.” This bilingual edition provides paragraph-aligned Traditional Chinese and English, six enterprise scenarios, governance templates, a 60-item production checklist, and hands-on labs.