Skip to content
Navigation menu
Search
Powered by Algolia
Search
Log in
Create account
DEV Community
Close
← All Trends
AI Agent Authorization and Security Flaws
44 posts in this trend in the last 7 days
•
Active about 5 hours ago
MCP Tool Descriptions Are Instructions, Not Metadata -- and That Is the Exploit
Davi
Davi
Davi
Follow
Sep 6
MCP Tool Descriptions Are Instructions, Not Metadata -- and That Is the Exploit
#
ai
#
llm
#
mcp
#
security
1
reaction
Comments
1
comment
5 min read
Gating Agent Shell Access: Why Containers Aren't Enough and Approval Loops Break
mech.app
mech.app
mech.app
Follow
Sep 4
Gating Agent Shell Access: Why Containers Aren't Enough and Approval Loops Break
#
agents
#
automation
#
cybersecurity
#
security
1
reaction
Comments
1
comment
7 min read
Harness Engineering: Designing the Runtime Capability Envelope Around an Agent
shakti mishra
shakti mishra
shakti mishra
Follow
Sep 6
Harness Engineering: Designing the Runtime Capability Envelope Around an Agent
#
ai
#
security
#
architecture
#
devops
1
reaction
Comments
1
comment
11 min read
How execution boundaries reduce the blast radius of AI agent mistakes
AndersonVitaease
AndersonVitaease
AndersonVitaease
Follow
Sep 5
How execution boundaries reduce the blast radius of AI agent mistakes
#
ai
#
agents
#
security
#
mcp
Comments
Add Comment
3 min read
# Agent Firewall v2.5: I Attacked My Own AI Agent Security Boundary
Shubhbhangoo
Shubhbhangoo
Shubhbhangoo
Follow
Sep 4
# Agent Firewall v2.5: I Attacked My Own AI Agent Security Boundary
#
ai
#
programming
#
security
#
agents
Comments
Add Comment
3 min read
AI Agents Are eval(userInput) With Extra Steps
Davi
Davi
Davi
Follow
Sep 6
AI Agents Are eval(userInput) With Extra Steps
#
agents
#
ai
#
llm
#
security
Comments
Add Comment
5 min read
OAuth Token Leakage in Agentic AI: When the Context Window Becomes a Credential Store
Davi
Davi
Davi
Follow
Sep 6
OAuth Token Leakage in Agentic AI: When the Context Window Becomes a Credential Store
#
ai
#
cybersecurity
#
llm
#
security
Comments
Add Comment
4 min read
Agentic AI Security: Sandboxing LLM Tool Calls in Production
Ayi NEDJIMI
Ayi NEDJIMI
Ayi NEDJIMI
Follow
Sep 6
Agentic AI Security: Sandboxing LLM Tool Calls in Production
#
security
#
ai
#
python
#
devops
Comments
Add Comment
4 min read
AI Agent HTTP Tools Are SSRF by Construction: Network Policy Is the Only Real Control
Davi
Davi
Davi
Follow
Sep 6
AI Agent HTTP Tools Are SSRF by Construction: Network Policy Is the Only Real Control
#
agents
#
ai
#
cybersecurity
#
security
Comments
1
comment
5 min read
LLM Agent Sandboxes Have Two Escape Surfaces. Only One Gets CVEs.
Davi
Davi
Davi
Follow
Sep 6
LLM Agent Sandboxes Have Two Escape Surfaces. Only One Gets CVEs.
#
agents
#
llm
#
mcp
#
security
Comments
2
comments
5 min read
Shadow Agent Problem
Stephen Lincoln
Stephen Lincoln
Stephen Lincoln
Follow
Sep 9
Shadow Agent Problem
#
agents
#
ai
#
cybersecurity
#
security
1
reaction
Comments
4
comments
2 min read
Docker Sandboxes for AI Agents: The Right Way to Isolate Untrusted Code Execution
Davi
Davi
Davi
Follow
Sep 6
Docker Sandboxes for AI Agents: The Right Way to Isolate Untrusted Code Execution
#
agents
#
ai
#
docker
#
security
Comments
Add Comment
5 min read
MCP Tool Schema Poisoning: When the Framework Layer Authorizes the Attack
Davi
Davi
Davi
Follow
Sep 6
MCP Tool Schema Poisoning: When the Framework Layer Authorizes the Attack
#
cybersecurity
#
llm
#
mcp
#
security
Comments
Add Comment
6 min read
AI Agent Checkpoint Tampering: The State File Is the Attack Surface
Davi
Davi
Davi
Follow
Sep 6
AI Agent Checkpoint Tampering: The State File Is the Attack Surface
#
ai
#
cybersecurity
#
security
#
vulnerabilities
Comments
Add Comment
5 min read
JSON, CSV, and YAML Are Not Safe Formats for AI Agents: They Are Attack Vectors
Davi
Davi
Davi
Follow
Sep 6
JSON, CSV, and YAML Are Not Safe Formats for AI Agents: They Are Attack Vectors
#
ai
#
cybersecurity
#
llm
#
security
1
reaction
Comments
1
comment
5 min read
Specification Gaming Is an Attack Surface, Not an Alignment Footnote
Davi
Davi
Davi
Follow
Sep 6
Specification Gaming Is an Attack Surface, Not an Alignment Footnote
#
agents
#
ai
#
llm
#
security
Comments
Add Comment
5 min read
Why command allowlists don't protect your AI coding agent
DarkAxiom93
DarkAxiom93
DarkAxiom93
Follow
Sep 5
Why command allowlists don't protect your AI coding agent
#
agents
#
ai
#
security
Comments
Add Comment
2 min read
The Agent Doesn't Have to Be Malicious for the Action to Be Dangerous
陈逸昕
陈逸昕
陈逸昕
Follow
Sep 8
The Agent Doesn't Have to Be Malicious for the Action to Be Dangerous
#
ai
#
agents
#
security
#
opensource
1
reaction
Comments
Add Comment
6 min read
« First
‹ Prev
1
2
3
Next ›
Last »
We're a place where coders share, stay up-to-date and grow their careers.
Log in
Create account