Solid work- underrated tbh I came across it by total chance in my feed
One thing i notice instantlly:
- instead of asking how vulnerable the model is
- this project should make IT departments think about how security changes as delegation depth increases --> feels like the more interesting q orgs have no clue how to answer, they should be reading this stuff + other papers, linking some here
intent laundering vs trust laundering is the actual debate, see:
attacker
↓
agent
↓
agent
↓
user
the attack survives bc trust compounds across hops and statistically gets scored as safe, which inverts the entire defense models out there rn
but now let's start one layer earlier:
registry
- tool metadata (plaintext json fields, headers, sideloading things usually taken for granted and not authenticated equally)
- selection
- delegation (maybe )
instead of
prompt
- straight to agent (easier to catch/train for)
when you combine mcp/skills + entire marketplaces of agents + plugins like github, npm, vscode lol (all getting pwned in last 1month) the entire matrix of attack vectors is exponentially rising
And the msot dangerous ones seem like theyre gonna begin at discovery / trust boundaries and avoid the whole prompt ingestion route compeletely
very solid. keep up the good work 👍
Solid work- underrated tbh I came across it by total chance in my feed
One thing i notice instantlly:
intent laundering vs trust laundering is the actual debate, see:
the attack survives bc trust compounds across hops and statistically gets scored as safe, which inverts the entire defense models out there rn
but now let's start one layer earlier:
instead of
prompt - straight to agent (easier to catch/train for)when you combine mcp/skills + entire marketplaces of agents + plugins like github, npm, vscode lol (all getting pwned in last 1month) the entire matrix of attack vectors is exponentially rising
And the msot dangerous ones seem like theyre gonna begin at discovery / trust boundaries and avoid the whole prompt ingestion route compeletely
very solid. keep up the good work 👍