Analysis · curated 28 Sep 2026
Confused Deputy: The Old Bug That AI Agents Keep...
First reported daily.dev
Coverage timeline
Single-source analysis — first reported, latest, and curated coincide.
Why it matters
The Confused Deputy pattern shows how AI agents with standing permissions and shell access can be turned into a supply-chain attack vector through simple prompt injection, a risk defenders must mitigate with least-privilege and credential isolation.
An Auth0 explainer argues that the 1988 Confused Deputy problem is resurfacing through AI agents that hold broad standing permissions and process trusted commands, data, and untrusted content through one undifferentiated natural-language channel. It cites the February 2026 'Clinejection' incident where a GitHub issue-triage bot with shell access was manipulated via a crafted issue title, leading to a poisoned GitHub Actions cache, a stolen npm publishing token, and a tampered package downloaded ~4,000 times, and recommends least privilege, task-scoped short-lived credentials, keeping credentials out of model reach, and human-in-the-loop approval.