AI + DISCOVERY / FIELD GUIDE 08

AI Disk Browser

Ask useful questions about files while keeping evidence, processing, and the authority to act under review.

Define a small discovery task

Begin an AI disk browser evaluation with a question you can verify manually over a copied, non-sensitive collection. Require the exact source path and supporting passage. Keep locating, interpreting, suggesting, and modifying as separate operations. A fluent answer should not be treated as proof that the right files were inspected.

Make authority boundaries explicit

OWASP’s prompt-injection guidance addresses instructions embedded in external content. For your review, ask how a product keeps retrieved file text from becoming tool authority. Treat the controls in our guide as evaluation requirements, not as claims that every AI product implements them.

Verify the evidence and the unknowns

Prepare questions with known answers and questions the collection cannot answer. Check cited paths and passages yourself. Record incorrect attribution, missing extraction, and unsupported explanations separately. Ask where file content, filenames, prompts, and derived indexes are processed rather than assuming a local-looking interface implies fully local processing.

Grant write access through a separate decision

Use read-only tasks first. Any later write evaluation should name the exact operation, target, expected result, and recovery arrangement. Review a small batch of disposable files and verify the outcome. Do not turn approval for summarizing one collection into permission to reorganize an entire drive.

Questions worth asking

Does AI make file organization automatically safe?

No automatic safety conclusion follows from the use of AI. Evaluate the actual access controls, source handling, processing locations, and action approvals for the task you intend.

How is this different from the AI LLM disk browser guide?

This page is for evaluating a user-facing workflow. The AI LLM guide focuses on the system architecture: extraction, indexing, retrieval, authorization, and source freshness.