Confused deputy
A privileged agent tricked by untrusted input into misusing its own authority on an attacker's behalf, e.g. exfiltrating data via a permitted egress path.
grounded in: doctrine Guardrails 'no ... new external network calls' + the 'AI agent wire-level transparency' trend (what agent CLIs transmit) — the classic access-control failure underlying the lethal trifecta
Connected concepts
Lethal Trifecta, Prompt injection, Agent identity & access mgmt, Capability-Based Security
Explore it live in the knowledge graph →