ai-agents
4 posts tagged ai-agents.
-
When Prompts Become Shells: How Prompt Injection Turned AI Agents Into Remote Code Execution
Prompt injection is not a content-safety nuisance. In tool-using AI agents it is a remote-code-execution class -- traced through four disclosed 2025-2026 CVEs.
-
Two Identical Requests: How Web Bot Auth and HTTP Message Signatures Let Servers Trust the Right Bots
How RFC 9421 and Web Bot Auth give bots and AI agents a standardized, directory-backed cryptographic identity -- and why it proves who, never whether-allowed.
-
Who Authorized This Tool Call? OpenID AuthZEN, the MCP Profile, and the Standards Race to Govern AI Agents
A valid OAuth token proves an AI agent is a legitimate caller but never authorizes the tool call. How OpenID AuthZEN and its MCP profile answer at runtime.
-
Agentic Identity on Windows: When the Process Acting on Your Behalf Isn't You
Every AI agent on Windows in 2026 runs as the logged-on user. The cloud-identity layer has crossed the agent-attribution gap; the OS layer has not. This article maps the FIDO AATWG pillars onto Windows primitives and asks what is missing.