Semantic Cluster

Agent Security Failure Modes

Terms that describe what can go wrong when agents act with broad access.

5 terms in this cluster

Agent Drift

Agent drift occurs when an AI agent's tool invocations deviate from the intended scope of its assigned task, invoking tools or accessing resources that are outside the bounds of the original task definition.

agent driftagent scope creepagent task drift

Excessive Agency

Excessive agency is a failure mode where an AI agent is given too much capability, autonomy, or access—allowing it to take actions with a broader impact than is appropriate or intended.

excessive agencyover-capable agentagent over-permissioning

Prompt Injection

Prompt injection is an attack where malicious content embedded in an agent's input or context manipulates the agent to take actions outside its intended task—including invoking unauthorized tools.

prompt injectionLLM prompt injectionagent prompt injection

Tool Description Poisoning

Tool description poisoning is an attack where malicious instructions are embedded in an MCP tool's description field, causing the agent to invoke the tool in an attacker-intended way or to misinterpret the tool's purpose.

tool description poisoningMCP tool poisoningtool metadata attack

Confused Deputy Problem

The confused deputy problem in agentic systems occurs when an AI agent uses its own elevated privileges to perform actions on behalf of a less-privileged principal, allowing that principal to effectively access resources it should not be able to reach.

confused deputyprivilege amplification via agentagent delegation exploit

AI Agent Access Control Glossary

Explore all 9 clusters

Browse the full glossary to understand the complete vocabulary of execution-time access control for AI agents.

Back to Glossary hub
Runtime Enforcement

Secure every agent tool call at execution time.

AgntID gives infrastructure teams scoped, ephemeral access control for AI agents without replacing IAM, MCP servers, tools, or agent frameworks.