Loading...
Excessive Agency Exploitation
EAEExploitation of agents that have been granted excessive permissions, capabilities, or autonomy beyond what is necessary for their intended function.
Example Scenario
A customer support agent granted broad database access "for flexibility" is manipulated to execute administrative functions, modify system configurations, or access sensitive employee data.
Testing Objectives
- Test principle of least privilege
- Assess capability scoping
- Evaluate permission boundaries
- Validate autonomy constraints
Defensive Strategies
- Strict permission minimization
- Role-based capability constraints
- Regular permission audits
- Autonomy limits and guardrails
- Capability usage monitoring
Key Features
- Over-permission abuse
- Scope creep exploitation
- Capability misuse
- Autonomy boundary violation
Use Cases
- Permission minimization validation
- Scope definition testing
- Capability boundary assessment
- Autonomy limit evaluation
Tools & Frameworks
Security Risks
Ethical Guidelines
- •Only test permission models with authorization
- •Never abuse production agent capabilities
- •Report over-permission issues to system owners
- •Focus on improving permission models
- •Consider principle of least privilege
Remember: This information is for educational and defensive security purposes only. Always ensure you have proper authorization before testing any techniques.
From the engineer behind this catalog
Get your agent system red-teamed
The attacks documented here work on production agent systems every day. Have yours tested before someone else does: prompt injection, jailbreaks, tool misuse and data exfiltration, with every finding written up next to its fix.
€750 instead of €1,500, one week, written report and walkthrough call, until 30 September