AI Agents Lack Data/Instruction Boundary, Sparking New Open Security Standard AVE

SelectionBitter6821 · reddit · 2026-08-05

The author points out that while traditional software security relies on separating data from instructions, LLMs treat document text and user commands as the same thing. This makes existing security categories like CVE and CWE ill-equipped to handle agent-related vulnerabilities.

To address this, the author and other developers created AVE, an open standard that directly names these behavioral patterns. It currently features 70 records crosswalked into OWASP's and MITRE's frameworks, aiming to fill the gap in AI agent security.

Original post →

More from coding & agent

coding & agent channel →