LCAC Context Scoper

Give each AI task only the minimum context it requires.

  • 1

    Describe the task

    What the agent must do, which model it goes to, and whether a human verifies the result.

  • 2

    Classify the context

    For each item: how sensitive it is, whether the task truly requires it, and whether its source can be trusted.

  • 3

    Check the stack

    Tick the Cognitive Security Stack controls in place, then copy the scoped context manifest.

The scoper

What does this agent need to know?

Anything not required is left out, secrets are never passed, and sensitive items travel only as scoped, ephemeral tokens. The result updates as you go.

1The task
Where does the request go?
Who decides on the output?
2The context

No context items yet. Add each file, dataset, prompt, key or hand-over you would give the model, or load the worked example.

3The stack

Tick each control that is in place for this task.

Why Zero Trust is not enough

The question is no longer who can act, but what an agent can know.

In vibe orchestration, AI is persistent: it makes decisions, executes logic and manages environments. This exposes a new threat surface — the cognitive layer. Cognitive security is the discipline of protecting that layer, and the human operating system around it, from manipulation, deception and systemic disruption.

Core concept

Zero Trust verifies every request and restricts privilege by identity — insufficient for AI that reasons, reflects and writes its own logic. LCAC extends Zero Trust into the reasoning layer by restricting the data supplied to a model’s context to the absolute minimum a task requires, preventing context leakage and manipulation.

How the verdict is reached
  • Not needed, or only helpful

    excluded. LCAC admits the absolute minimum a task requires.

  • Secrets

    always excluded; a tool that needs one gets a scoped, ephemeral token at execution.

  • Required and confidential or regulated

    included only as scoped, ephemeral tokens.

  • Red

    regulated data bound for an external model, a Critical-tier task with missing controls, or nothing left to run on.

  • Amber

    any open warning (external model, untrusted source, subagent hand-over) or any missing stack control.

The paper states the LCAC principle and the stack; it sets no numeric thresholds. These rules are this tool’s operational reading of it.

Figure 11

The Cognitive Security Stack

Built on Least-Context Access Control and extending Zero Trust into the reasoning layer. Each layer is one of the controls in step three.

  1. 5
    Auditable record of reasoning states

    Context registry

    Logs the model’s reasoning states and decision paths without storing sensitive prompt content, giving an unalterable, auditable record of the AI’s “thought process”.

  2. 4
    No ungoverned transfer between subagents

    Cognitive sandboxing

    Prevents the ungoverned transfer of knowledge, intent or system variables between subagents, mitigating data drift and cross-context bias.

  3. 3
    Scoped, ephemeral tokens destroyed after use

    Context tokenization

    Prompts, system files and retrieval vectors are broken into scoped, ephemeral tokens, so data stays isolated and is destroyed after execution.

  4. 2
    Only the minimum context a task requires

    Least-Context Access Control (LCAC)

    LCAC extends Zero Trust into the reasoning layer by restricting the data supplied to a model’s context to the absolute minimum a task requires, preventing context leakage and manipulation.

  5. 1
    Verify every request by identity

    Zero Trust · identity & network

    Zero Trust verifies every request and restricts privilege by identity — insufficient for AI that reasons, reflects and writes its own logic.

Figure 8

Four risk tiers, each with a mandatory pathway.

Every declared instance is scored on a five-dimensional taxonomy — data sensitivity, decision impact, processing transparency, organizational function and third-party supply-chain reliance — and placed in one of four risk tiers. The scoper reads the first two dimensions from what is left in the context.

  • Critical

    Block

    Network restriction and incident investigation

    Criteria: Regulated or confidential data, autonomous decisions, high-stakes settings

  • High

    Replace

    Substitute an approved enterprise equivalent

    Criteria: Confidential data or determinative business decisions

  • Moderate

    Regularise

    Onboard with vendor due diligence and DPAs

    Criteria: Internal data, advisory output with human verification

  • Low

    Monitor

    Approved catalog plus targeted training

    Criteria: Public, non-sensitive data; no core business logic

OWASP Top 10 for LLM Applications (2025)

What an over-full context opens.

Each category corresponds to an exposure pathway that shadow tools open by default. These are the ones that grow with every unnecessary item in a model’s context.

  • LLM01

    Prompt Injection

    Adversarial inputs (direct or indirect) that overwrite system prompts

    Impact: Safety bypasses, unauthorized commands, malicious code in the developer environment

  • LLM02

    Sensitive Information Disclosure

    Leakage of proprietary algorithms, PII or architecture via output

    Impact: Exposes corporate secrets, voids IP and triggers regulatory penalties

  • LLM06

    Excessive Agency

    Broad permissions to call APIs or databases with no human in the loop

    Impact: Rogue agents delete production data or alter access control

  • LLM07

    System Prompt Leakage

    Disclosure of the instructions that bound the model’s behaviour

    Impact: Adversaries reverse-engineer defences, steal prompt IP, craft bypasses

  • LLM08

    Vector and Embedding Weaknesses

    Flaws in generation, storage or retrieval within RAG

    Impact: Poisoned vector stores surface malicious context and instructions

  • LLM10

    Unbounded Consumption

    Overloading costly inference to overwhelm services (Denial of Wallet)

    Impact: Billing spikes, exhausted cloud capacity, severe latency

Executive recommendation 05

Extend Zero Trust into reasoning

Adopt Least-Context Access Control, cognitive sandboxing and a context registry for every agent.

About the checklist

From my white paper Vibe Orchestration (2026), Section 7, “Vibe Orchestration and the Cognitive Security Stack” (Figure 11), with the risk tiers of Section 5 (Figure 8), the AI usage policies of Section 6, and OWASP Table 3.

How to cite

Elgendi, M. F. (2026). Vibe Orchestration. A white paper. www.fawzooz.ai