Loading...
Confused Deputy Attack
CDATricking a privileged agent into performing unauthorized actions on behalf of an attacker by exploiting the agent's trust in its inputs or tools.
Example Scenario
A low-privilege agent convinces a high-privilege agent to execute a database deletion by framing it as a legitimate data cleanup request, exploiting the trusted relationship between agents.
Testing Objectives
- Test authorization delegation
- Assess tool invocation controls
- Evaluate trust verification
- Validate privilege checking
Defensive Strategies
- Explicit authorization for tool use
- Request origin validation
- Action authorization verification
- Tool sandboxing and constraints
- Audit trails for privileged actions
Key Features
- Privilege abuse through trusted paths
- Tool invocation manipulation
- Authority exploitation
- Trust relationship abuse
Use Cases
- Agent authorization model testing
- Tool invocation security assessment
- Trust relationship validation
- Privilege verification testing
Tools & Frameworks
Security Risks
Ethical Guidelines
- •Only test deputy patterns with authorization
- •Never exploit production trust relationships
- •Report confused deputy vulnerabilities promptly
- •Focus on strengthening authorization models
- •Consider harm from privilege misuse
Remember: This information is for educational and defensive security purposes only. Always ensure you have proper authorization before testing any techniques.
From the engineer behind this catalog
Get your agent system red-teamed
The attacks documented here work on production agent systems every day. Have yours tested before someone else does: prompt injection, jailbreaks, tool misuse and data exfiltration, with every finding written up next to its fix.
€750 instead of €1,500, one week, written report and walkthrough call, until 30 September