Open-Source Agentic AI Security Lab: 9 Scenarios Breaking Agent Authorization

Rewanth_Tammana · reddit · 2026-09-16

Security researcher Rewanth Tammana released 'Who Let the Agents Act?', an intentionally vulnerable agentic AI environment comparing three implementations per scenario: overprivileged, prompt-only security, and hardened with authorization enforced outside the model. Nine scenarios cover overprivileged tools, PII exposure, business-logic bypasses, indirect prompt injection, cross-tenant RAG leakage, secret propagation, fail-open authorization, agent delegation, and multi-agent confused deputy attacks. All code and execution traces are public, built on the principle that a prompt can influence an agent's behavior but should never define its authority.

Original post →

More from coding & agent

coding & agent channel →