Analysis
OWASP ASI03 Confused Deputy in AI Agents — Authority Boundary | Kimss AI — Secure Enterprise Agent Control Plane
Publication date unknown · Discovered kimss.ai
Page published
Publication date unknown · First observed: 9 Oct 2026
Coverage timeline
Single-source analysis — one report is available.
Why it matters
The confused-deputy pattern lets prompt-injected content hijack an agent's legitimate tool privileges to exfiltrate data, a core risk defenders of agentic systems must enforce authorization against at the moment of tool invocation.
A vendor explainer from Kimss describes OWASP's ASI03 "Confused Deputy" (Identity & Privilege Abuse) class from the Top 10 for Agentic Applications 2026, where an agent with legitimate tool access is tricked by prompt-injected untrusted input into supplying malicious arguments (e.g., a support agent's send_email tool exfiltrating internal threads to an attacker address). Kimss promotes its "Authority Boundary" argument-level authorization approach as the mitigation, contrasting it with edge proxying and orchestration frameworks like LangGraph/LangChain.