10 Comments
User's avatar
Amit Spitzer's avatar

The permission-scoping point is the one that holds up under real operating conditions. What doesn't get discussed enough is drift: every environment I've run tends toward broader agent access within a quarter, because someone escalates a legitimate need and wins, and nobody re-audits the grant six months later. Worth asking any agent security vendor for their access-drift numbers, not just their injection detection rate.

ToxSec's avatar

i fully agree. do a security review, scope it, set it up nice and secure. then next week it has access to everything..

its utility vs security. teams want agents to do things, so granting access one little increase in access seems harmless. but it adds up fast and the drift is real.

Nelson Lopes's avatar

"the attacker phrased the hidden instructions so they never resembled an obvious injection pattern, and the filter missed it entirely."

"an agent with fewer permissions is also less useful, and organizations under pressure to show off AI value sometimes grant broader access than their security posture would otherwise allow."

Same movie, new actor :D

Makes me wonder which other old lessons we're about to re-learn at AI speed.

Great article!

ToxSec's avatar

love that line. we are absolutely re-learning here.

Mohib Ur Rehman's avatar

Thanks for reading!

Zyrox's avatar

I didn't know prompt injection is that dangerous. Great article guys!

ToxSec's avatar

yeah it’s wild how it can be either a fluff attack or really dangerous!

ToxSec's avatar

this landed really well!