AI AGENT SECURITY · FIELD GUIDE + HANDS-ON LABS

Find the boundary that breaks

Explore nine realistic AI agent security failures. Read the Field Guide or test each one in hands-on labs across vulnerable, prompt-only, and hardened designs.

NINE SECURITY BOUNDARIES

Read the attack or run the lab

Each scenario pairs a practical Field Guide chapter with a live comparison of vulnerable, prompt-only, and hardened designs.

01 · Data privacyCRITICAL

Overpowered Data Tool

A bank-support agent can expose private customer fields when authorization and output controls are delegated to the model.

SECURITY BOUNDARY

Database-backed field authorization and output DLP

02 · Access controlCRITICAL

Cross-Account Access

A support agent acting with a broad service identity can become a confused deputy and read a different customer's records.

SECURITY BOUNDARY

Human-to-agent delegation and object-level authorization

03 · Agent identity & delegationHIGH

Unsafe Agent Handoff

A customer-support router hands a transfer request to a specialist, but an unsafe handoff can carry secrets and excess authority across the trust boundary.

SECURITY BOUNDARY

Signed envelope, audience binding, expiry, and receiver-side scope

04 · Transaction integrityCRITICAL

Refund Limit Bypass

An autonomous refund agent can decompose an oversized goal into individually plausible tool calls.

SECURITY BOUNDARY

Cumulative per-transaction limit and idempotent execution

05 · Input & retrieval securityHIGH

Poisoned Invoice Instructions

Instructions hidden in an uploaded invoice try to steer the agent toward an unauthorized payment.

SECURITY BOUNDARY

Content/instruction separation and beneficiary authorization

06 · Retrieval securityCRITICAL

Multi-tenant RAG Leakage

A shared policy index can return a more similar document from another bank tenant.

SECURITY BOUNDARY

Tenant eligibility before query-dependent ranking

07 · Secrets & observabilityCRITICAL

Secret Leakage Through Debugging

A diagnostics observation can carry a secret into a second agent action and an outbound incident report.

SECURITY BOUNDARY

Least-privilege observation projection plus enforced DLP

08 · Fail-safe behaviorCRITICAL

Approval Service Outage

A payment agent continues when its authorization service times out, turning infrastructure failure into unauthorized execution.

SECURITY BOUNDARY

Affirmative authorization at the payment tool, with fail-closed timeout handling

09 · Trust propagationCRITICAL

Confused Deputy Agent Chain

A poisoned merchant note crosses two agent handoffs and persuades an account-control agent to freeze another customer's account.

SECURITY BOUNDARY

Typed taint-aware handoff plus receiver-side target and action authorization

CHOOSE A DEFENSE POSTURE

AGENT CONSOLE

Send the agent a request.

⌘ ENTER

AGENT RESPONSE

Outcome, response, and comparison results appear here.

WAITING
Run or compare this request

Use one mode for its full execution trace, or compare all three security postures.

AGENTIC MECHANISM

MODEL DECIDES

SECURITY BOUNDARY

VIEW LIVE AGENT CONFIGURATION

SCENARIO DATABASE & POLICY

ACTIVE SYSTEM PROMPT

OPEN SOURCE

Compare the source

Read the vulnerable and hardened implementations or propose another scenario.

OPEN SOURCE

Compare the source

Read the vulnerable and hardened implementations or contribute a scenario.