Start here. This is the direct spoken answer to practice first.
Overview
A read tool plus an outbound tool can form an exfiltration path even when each tool appears safe in isolation.
I identify sensitive sources and external sinks, then prevent the model from freely combining them. A workflow that reads private documents does not automatically receive arbitrary HTTP, email, upload, or link-generation tools. Each outbound action validates destination, data classification, user authority, and purpose, with a clear preview and approval when sensitive data could leave its boundary.