Secure Laravel AI Agents: 4 Defense Layers Explained | Mohamed Said       [Skip to content](#main)  [ ![](https://cdn.msaied.com/01KT78WE565VEMM3PSNQAAB0MH.png) Mohamed SaidLaravel Backend Engineer ](https://www.msaied.com/public) - [Home](https://www.msaied.com/public)
- [Projects](https://www.msaied.com/public/projects)
- [Articles](https://www.msaied.com/public/articles)
- [Certificates](https://www.msaied.com/public/certificates)
- [About](https://www.msaied.com/public#about)

           [  Contact](https://www.msaied.com/public#contact) Menu 

Menu
----

Close 

 - [HomeStart here](https://www.msaied.com/public)
- [ProjectsCase studies](https://www.msaied.com/public/projects)
- [ArticlesEngineering notes](https://www.msaied.com/public/articles)
- [CertificatesCredentials](https://www.msaied.com/public/certificates)
- [AboutHow I work](https://www.msaied.com/public#about)
- [ContactGet in touch](https://www.msaied.com/public#contact)

  [Start a conversation](https://www.msaied.com/public#contact) [WhatsApp](https://wa.me/201094619204) [Email](mailto:hello@msaied.com) 

 1. [Home](https://www.msaied.com/public)
2. /
3. [Articles](https://www.msaied.com/public/articles)
4. /
5. [Laravel](https://www.msaied.com/public/articles?category=laravel)
6. /
7. Ship AI with Laravel: How to Stop Your AI Agent from Leaking Everything

   [Laravel](https://www.msaied.com/public/articles?category=laravel) [AI](https://www.msaied.com/public/articles?category=ai) 

 Ship AI with Laravel: How to Stop Your AI Agent from Leaking Everything
========================================================================

 Episode 11 of Ship AI with Laravel demonstrates two real AI vulnerabilities—prompt extraction and unauthorized data access—then closes them with four concrete defense layers using Laravel, Ollama, and Llama 3.2.

 ![](https://cdn.msaied.com/01M22N44A70A5MC2S599JP0MPH.webp) [Mohamed Said](https://www.msaied.com/public#person) Published 8 Jul 2026 · Updated 8 Jul 2026 · 3 min read

ShareCopy linkCopied

 ![Ship AI with Laravel: How to Stop Your AI Agent from Leaking Everything](https://cdn.msaied.com/396/d81ab14c56dd0070a774276d597c77b2.png) 

  On this page +1. [The Problem: AI Agents Ship with Real Vulnerabilities](#the-problem-ai-agents-ship-with-real-vulnerabilities)
2. [Four Layers of Defense](#four-layers-of-defense)
3. [Layer 1: Prompt Hardening](#layer-1-prompt-hardening)
4. [Layer 2: Local LLM Guard with Ollama and Llama 3.2](#layer-2-local-llm-guard-with-ollama-and-llama-32)
5. [Layer 3: Tool-Level Authorization](#layer-3-tool-level-authorization)
6. [Layer 4: Output Filtering](#layer-4-output-filtering)
7. [Series Wrap-Up](#series-wrap-up)
8. [Key Takeaways](#key-takeaways)

 The Problem: AI Agents Ship with Real Vulnerabilities
-----------------------------------------------------

Most Laravel developers building AI-powered features focus on getting the agent to *work*. Security comes later—if at all. Episode 11 of the *Ship AI with Laravel* series by Harris Raftopoulos makes the cost of that approach painfully clear.

Before introducing any fixes, the episode demonstrates two attacks against a live support agent:

1. **Prompt extraction via social engineering** — A carefully crafted sequence of messages convinces the agent to reveal its entire system prompt, its tool list, and its internal instructions.
2. **Unauthorized data access via tool abuse** — The order lookup tool is called with an order ID belonging to a different customer, and it returns that customer's data without any authorization check.

Both vulnerabilities are straightforward to exploit and, according to the episode, ship in production AI apps every day.

Four Layers of Defense
----------------------

### Layer 1: Prompt Hardening

The first fix is the simplest: add explicit security boundaries directly to the system prompt. The agent is instructed to refuse requests to reveal its prompt or tools, and to treat anyone claiming to be an internal employee as a regular customer.

This reduces casual attacks but is not sufficient on its own. A determined attacker can still social-engineer around a prompt-only defense.

### Layer 2: Local LLM Guard with Ollama and Llama 3.2

A separate prompt-guard agent is introduced, running locally via Ollama with Llama 3.2. Its sole responsibility is to classify each incoming message as `safe` or `unsafe` and return a JSON result.

```json
{ "classification": "unsafe", "reason": "prompt injection attempt" }

```

This guard is wired in as middleware, so unsafe messages are blocked before they ever reach the main agent. Because it runs locally, there is no per-request API cost for this screening step.

### Layer 3: Tool-Level Authorization

This is the fix that actually closes the data leak. The order lookup tool is scoped to the authenticated user:

```php
// Tool enforces ownership — no matter what ID is passed in
$order = Order::where('id', $orderId)
    ->where('user_id', auth()->id())
    ->firstOrFail();

```

With this in place, the tool physically cannot return another customer's order, regardless of what order ID an attacker supplies. Prompt instructions alone cannot provide this guarantee; authorization logic in the tool itself can.

### Layer 4: Output Filtering

A safety-net middleware scans every outgoing response and redacts sensitive patterns—SSNs, credit card numbers, API keys—before anything leaves the system. This acts as a last line of defense against accidental data exposure that slips through earlier layers.

Series Wrap-Up
--------------

Episode 11 closes out the eleven-episode *Ship AI with Laravel* series. The arc runs from `composer require laravel/ai` all the way to a production-ready, tested, and secured AI platform. If you are joining late, the author recommends starting at Episode 1 since each episode builds on the previous one.

The full source code is available on GitHub: [github.com/harris21/ship-ai-with-laravel](https://github.com/harris21/ship-ai-with-laravel)

Key Takeaways
-------------

- **Prompt hardening alone is not enough** — social engineering can bypass instruction-only defenses.
- **Authorization belongs in the tool, not the prompt** — scope database queries to the authenticated user at the code level.
- **A local LLM guard adds zero API cost** — Ollama + Llama 3.2 can classify messages as middleware before they hit your main model.
- **Output filtering is a safety net** — redact sensitive patterns on egress as a final layer.
- **Defense in depth is the standard** — stack multiple independent layers so no single failure exposes user data.

---

*Source: [Ship AI with Laravel: I Tricked My Own AI Into Leaking Everything — Laravel News](https://laravel-news.com/ship-ai-with-laravel-i-tricked-my-own-ai-into-leaking-everything)*

- [Laravel AI](https://www.msaied.com/public/articles?search=Laravel%20AI)
- [AI Security](https://www.msaied.com/public/articles?search=AI%20Security)
- [Prompt Injection](https://www.msaied.com/public/articles?search=Prompt%20Injection)
- [Ollama](https://www.msaied.com/public/articles?search=Ollama)
- [Laravel Middleware](https://www.msaied.com/public/articles?search=Laravel%20Middleware)

 Frequently asked questions 
---------------------------

  Why isn't adding security instructions to the system prompt enough to protect a Laravel AI agent?A determined attacker can use social engineering to talk the model into ignoring prompt-level instructions. That's why the episode stacks three additional layers: a local LLM guard that blocks unsafe messages before they reach the main agent, tool-level authorization that enforces data ownership in code, and output filtering that redacts sensitive patterns on egress.

   How does the local LLM guard work and what does it cost to run?The guard is a separate agent running Llama 3.2 via Ollama on your own infrastructure. It classifies each incoming message as safe or unsafe and returns a JSON result. Because it runs locally rather than calling an external API, the per-request cost is zero.

   What is the most effective single fix for preventing unauthorized data access through an AI tool?Scoping the database query inside the tool itself to the authenticated user. For example, adding a `where('user\_id', auth()-&gt;id())` constraint to the order lookup query means the tool cannot return another customer's data regardless of what order ID is passed in.

   ![Mohamed Said](https://cdn.msaied.com/01M22N44A70A5MC2S599JP0MPH.webp)About the author
----------------

[Mohamed Said](https://www.msaied.com/public#person)Senior Backend Engineer specializing in Laravel, scalable SaaS platforms, APIs, and cloud infrastructure. I build secure, high-performance web applications that help businesses grow.

[About](https://www.msaied.com/public#about) [GitHub ↗](https://github.com/EG-Mohamed) [LinkedIn ↗](https://www.linkedin.com/in/msaiedm/) [WhatsApp ↗](https://wa.me/201094619204) [Email Address ↗](mailto:hello@msaied.com) [My CV ↗](https://drive.google.com/file/u/0/d/1MF20IPRJyzfy32mhEutjL5EpSls0w2Q8/view)  

   [Previous articleLaravel Concurrency Facade and Process Pools for Parallel Work](https://www.msaied.com/public/articles/laravel-concurrency-facade-and-process-pools-for-parallel-work-3) [Next articleLaravel Cloud Security Defaults Behind Every Deploy](https://www.msaied.com/public/articles/laravel-cloud-security-defaults-behind-every-deploy)  

   On this page
-------------

1. [The Problem: AI Agents Ship with Real Vulnerabilities](#the-problem-ai-agents-ship-with-real-vulnerabilities)
2. [Four Layers of Defense](#four-layers-of-defense)
3. [Layer 1: Prompt Hardening](#layer-1-prompt-hardening)
4. [Layer 2: Local LLM Guard with Ollama and Llama 3.2](#layer-2-local-llm-guard-with-ollama-and-llama-32)
5. [Layer 3: Tool-Level Authorization](#layer-3-tool-level-authorization)
6. [Layer 4: Output Filtering](#layer-4-output-filtering)
7. [Series Wrap-Up](#series-wrap-up)
8. [Key Takeaways](#key-takeaways)

 ###  Have a technical challenge?

 Tell me what you’re building. I reply within two working days.

[Start a conversation](https://www.msaied.com/public#contact) 

   Related articles
-----------------

 [ ![](https://cdn.msaied.com/740/cce86edc21eddcbdd2f2454fadaf9c70.png)  · 3 min read### The Pipeline Pattern in Laravel: Custom Pipelines Beyond Middleware

5 Oct 2026 ](https://www.msaied.com/public/articles/the-pipeline-pattern-in-laravel-custom-pipelines-beyond-middleware-1) [ ![](https://cdn.msaied.com/739/2d6897fdcdcf090613f96f72a64b8a78.png)  · 4 min read### MySQL Full-Text Search in Laravel: Indexes, Relevance Scoring, and Boolean Mode

4 Oct 2026 ](https://www.msaied.com/public/articles/mysql-full-text-search-in-laravel-indexes-relevance-scoring-and-boolean-mode) [ ![](https://cdn.msaied.com/738/073696a3fefe18bec825beec5ac658f5.png)  · 4 min read### Laravel Queue Rate-Limited Middleware: Throttling Jobs Without Losing Work

4 Oct 2026 ](https://www.msaied.com/public/articles/laravel-queue-rate-limited-middleware-throttling-jobs-without-losing-work) 

  Have a technical challenge?
----------------------------

Tell me what you’re building. I reply within two working days.

 [Discuss your project ↗](https://www.msaied.com/public#contact) 

  © 2026 Mohamed Said · Built with Laravel, meant to last.Senior Backend Engineer specializing in Laravel, scalable SaaS platforms, APIs, and cloud infrastructure. I build secure, high-performance web applications that help businesses grow.

 - [Home](https://www.msaied.com/public)
- [Articles](https://www.msaied.com/public/articles)
- [Certificates](https://www.msaied.com/public/certificates)
- [GitHub](https://github.com/EG-Mohamed)
- [LinkedIn](https://www.linkedin.com/in/msaiedm/)
- [WhatsApp](https://wa.me/201094619204)
- [Email Address](mailto:hello@msaied.com)
- [My CV](https://drive.google.com/file/u/0/d/1MF20IPRJyzfy32mhEutjL5EpSls0w2Q8/view)
- [Sitemap](https://www.msaied.com/public/sitemap.xml)
