Agent identity and privilege abuse

에이전트 신원·권한 남용

An agent acting under an overpowered identity can reach resources outside its task.

···
html
<div class="sd"><div class="sd-head"><strong>AGENT PRIVILEGE</strong><span id="state">live check</span></div><div class="sd-stage"><div class="ap-grid"><div>resource</div><div>wide token</div><div>task token</div><div>report</div><b>ALLOW</b><b>ALLOW</b><div>secrets</div><b class="ap-extra">ALLOW</b><b class="ap-deny">DENY</b><div>billing</div><b class="ap-extra">ALLOW</b><b class="ap-deny">DENY</b></div></div><div class="sd-foot"><span id="caption">checking boundary</span><span>tap to step</span></div></div>
css
.sd{box-sizing:border-box;width:min(94vw,700px);height:min(86vh,318px);padding:clamp(9px,2.3vmin,18px);border:1px solid var(--line);border-radius:14px;background:var(--surface);color:var(--fg);display:flex;flex-direction:column;gap:clamp(6px,1.8vmin,12px);font:600 clamp(12px,2.6vmin,16px)/1.25 var(--font-sans, sans-serif)}.sd *{box-sizing:border-box}.sd-head,.sd-foot{display:flex;align-items:center;justify-content:space-between;gap:8px;min-height:1.25em}.sd-head strong{color:var(--accent);letter-spacing:.06em}.sd-head span,.sd-foot{color:var(--muted)}.sd-foot{font-size:clamp(12px,2.4vmin,14px)}.sd-stage{position:relative;flex:1;min-height:0;display:flex;align-items:center;justify-content:center;gap:clamp(6px,2vmin,18px);overflow:hidden}.sd .mono{font-family:ui-monospace,monospace}.sd .tile{border:1px solid var(--line);border-radius:8px;background:var(--bg);padding:clamp(5px,1.5vmin,10px);text-align:center}.sd .good{color:var(--accent);border-color:var(--accent)}.sd .bad{color:var(--accent-3);border-color:var(--accent-3)}.sd .arrow{color:var(--muted);font-size:clamp(15px,4vmin,28px)}.sd .active{background:color-mix(in srgb,var(--accent) 16%,var(--surface));border-color:var(--accent)}.sd .blocked{background:color-mix(in srgb,var(--accent-3) 13%,var(--surface));border-color:var(--accent-3)}.ap-grid{width:min(96%,530px);display:grid;grid-template-columns:1fr 1fr 1fr;border:1px solid var(--line);border-radius:8px;overflow:hidden;text-align:center}.ap-grid>*{padding:clamp(3px,1.2vmin,8px);border-right:1px solid var(--line);border-bottom:1px solid var(--line);min-width:0}.ap-grid>*:nth-child(3n){border-right:0}.ap-grid>*:nth-child(-n+3){color:var(--muted);background:var(--bg)}.ap-grid b{color:var(--accent)}.ap-grid .ap-deny{color:var(--accent-3)}.ap-grid .ap-extra.on{background:color-mix(in srgb,var(--accent-3) 20%,var(--surface));color:var(--accent-3)}
js
let n=-1;function advance(){n=1-n;document.querySelectorAll('.ap-extra').forEach(e=>e.classList.toggle('on',!!n));document.getElementById('state').textContent=n?'excessive reach':'task-scoped view';document.getElementById('caption').textContent=n?'wide identity exposes unrelated data':'only report access is needed'}advance();setInterval(advance,950);
document.querySelector('.sd').addEventListener('pointerdown',advance);

Agent identity and privilege abuse arises when a delegated token or service identity can reach more resources than the agent’s task requires. Argument checks do not contain the damage if the executing identity itself has administrator access.

The demo compares broad and task-scoped identities for the same read task. Issue short-lived, resource-scoped credentials and audit their use.

When to use

Review it whenever an agent receives a service identity or delegated token for external resources.

Open as page ↗