Discussion about this post

User's avatar
Amit Spitzer's avatar

The permission-scoping point is the one that holds up under real operating conditions. What doesn't get discussed enough is drift: every environment I've run tends toward broader agent access within a quarter, because someone escalates a legitimate need and wins, and nobody re-audits the grant six months later. Worth asking any agent security vendor for their access-drift numbers, not just their injection detection rate.

Nelson Lopes's avatar

"the attacker phrased the hidden instructions so they never resembled an obvious injection pattern, and the filter missed it entirely."

"an agent with fewer permissions is also less useful, and organizations under pressure to show off AI value sometimes grant broader access than their security posture would otherwise allow."

Same movie, new actor :D

Makes me wonder which other old lessons we're about to re-learn at AI speed.

Great article!

8 more comments...

No posts

Ready for more?