AI Agents Lack Data/Instruction Boundary, Sparking New Open Security Standard AVE
SelectionBitter6821 · reddit · 2026-08-05
The author points out that while traditional software security relies on separating data from instructions, LLMs treat document text and user commands as the same thing. This makes existing security categories like CVE and CWE ill-equipped to handle agent-related vulnerabilities.
To address this, the author and other developers created AVE, an open standard that directly names these behavioral patterns. It currently features 70 records crosswalked into OWASP's and MITRE's frameworks, aiming to fill the gap in AI agent security.
More from coding & agent
- Unicity Launches Multi-Tenant Agent OS with 1000x Density — JoshuaJBouw · 2026-08-05
- mattpocock/skills Launches New Docs for AI Engineering Workflows — mattpocockuk · 2026-08-05
- mattpocock/skills v1.2 Released: New Slash Commands for AI Coding — mattpocockuk · 2026-08-05
- Dev Exhausts Codex Credits After 100-Hour Reverse Engineering Spree — yacineMTB · 2026-08-05
- OpenAI Agents Repo Skill Offers Risk-Tiered Code Review to Improve First-Pass Quality — gabrielchua · 2026-08-05
- Training Coding Agents with RL: OpenCode Harness in HF Sandboxes — SergioPaniego · 2026-08-05