Analysis

OWASP ASI03 Confused Deputy in AI Agents — Authority Boundary | Kimss AI — Secure Enterprise Agent Control Plane

Page published

Publication date unknown · First observed: 9 Oct 2026

Coverage timeline

9 Oct 2026kimss.aiobserved

Single-source analysis — one report is available.

Why it matters

The confused-deputy pattern lets prompt-injected content hijack an agent's legitimate tool privileges to exfiltrate data, a core risk defenders of agentic systems must enforce authorization against at the moment of tool invocation.

A vendor explainer from Kimss describes OWASP's ASI03 "Confused Deputy" (Identity & Privilege Abuse) class from the Top 10 for Agentic Applications 2026, where an agent with legitimate tool access is tricked by prompt-injected untrusted input into supplying malicious arguments (e.g., a support agent's send_email tool exfiltrating internal threads to an attacker address). Kimss promotes its "Authority Boundary" argument-level authorization approach as the mitigation, contrasting it with edge proxying and orchestration frameworks like LangGraph/LangChain.