Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Prevent confused-deputy attacks by making every agent action pass an authorization check that verifies the originating principal, the delegation chain, the specific operation, and the target resource. Do not let an agent’s own credentials—or a prompt telling it what to do—stand in for proof that the caller authorized that action.

How the confused-deputy failure happens in an agent chain

A confused deputy is a more-privileged service or agent that is induced to use its authority for a less-privileged requester. AWS describes the classic problem as an entity without permission coercing a more-privileged entity into performing an action. In an agent system, the deputy may be an orchestrator that accepts an instruction from a user, retrieved document, email, or tool response, then uses its own credentials to call a tool or delegate to a more-privileged agent.

Identity is not the same as authorization

A downstream service may recognize the orchestrator as a trusted caller, yet still have no evidence that the user or upstream principal authorized this particular operation on this particular resource. AWS’s cross-account example illustrates the distinction: a third-party service can be tricked into using a trusted role for a different customer’s request if it does not bind the request to the right customer context.

Prompt injection makes the failure more likely

Assume that a model can be prompt-injected. A malicious instruction in a page or tool result might ask an agent to export data, change an account, or direct a sub-agent to act on a resource outside the task. The agent’s identity and its ability to call a tool do not establish that the requested action was delegated. As Dantuluri and Sundi put it in their 2026 paper, “Security that depends on the model not being hijacked is not security.” That is the authors’ formulation, not a standards-body rule; the practical implication is to enforce the authorization decision outside the model’s reasoning.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - YubiKey 5C - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB, FIDO Certified - Protect Your Online Accounts (5C)
  • POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Bind each delegated action to a narrow grant

At every handoff, carry verifiable information about who originated the request and what authority was delegated. The exact representation depends on the system, but the downstream enforcement point should be able to decide whether this caller may perform this operation on this target for this task.

  • Principal and delegation context: Preserve the originating user or service identity and enough of the delegation chain to determine whose authority the request represents. Do not silently replace it with the agent’s identity.
  • Audience: Restrict a credential or authorization to the intended downstream service. A token meant for one service should not automatically authorize calls to another.
  • Operation: Permit only the specific API actions required for the task, rather than a broad role that happens to include them.
  • Target: Bind the grant to the relevant resource, account, tenant, or customer. Check the actual resource in the request, not merely the caller’s general trust status.
  • Lifetime and revocation: Use short-lived authority where practical, and make it possible to reject authority that has expired or been revoked.

A useful design rule is that a child agent’s effective authority must be no broader than the intersection of the parent’s grant and the grant approved for that child task. The child must not be able to add scopes, substitute a different target, or impersonate another principal. This is a design synthesis, not a complete recipe mandated by a single standard.

Enforce authorization at every boundary

Route sensitive tool and agent calls through a broker, gateway, service, or runtime boundary that validates each operation. That enforcement point should reject a request even if the model is fully compromised, and the agent should not have ambient credentials that let it bypass the check.

Rank #2
MAOFAED Cybersecurity The Few (The Few The Proud)
  • Programmer Gift - Cybersecurity The Few The Proud, The Paranoid. Get this to have the best information security workers present. Computer programmer, computer coder, and anyone in IT tech!
  • Material: Stainless Steel, it is lead free and nickel free, hypo allergenic, it doesn’t rust, change colour or tarnish.
  • Measurement: 30mm(1.18"). TIPS:manual measuring permissible error.
  • If you are a cybersecurity engineer and you love to work with computer science this will be a great gift for you to wear. People who like programming, hackers and hacking will like this fantastic IT security keychain.
  • Velvet bag- Only the most elegant velvet jewelry pouches are used to package and ship our bangle. If you have any quality problems, please feel free to contact us and we will give you a proper solution until you satisfied.
  1. Inventory the chain. List users and service principals, agents, credentials, tools, and downstream services. Mark shared credentials, agent-to-agent handoffs, and services that trust an agent without seeing the originating principal’s authority.
  2. Define explicit grants. For each task, state the permitted operations and targets. Scope credentials as narrowly as the downstream API allows; use distinct agent credentials rather than human credentials where appropriate.
  3. Authenticate and preserve context at each hop. Verify the caller, retain the original principal and delegation context, and check that the next service is the intended audience. Reject requests whose operation or target falls outside the grant.
  4. Make the enforcement point unavoidable. Keep authorization decisions outside agent-generated reasoning. Remove or constrain credentials and network paths that would allow an agent to call the downstream service around the policy check.
  5. Test adversarial requests. Exercise expired or revoked authority, replayed or mismatched delegation context, target substitution, requests broader than the parent grant, a child asking for a sibling’s resource, malicious tool output, and prompt-injected instructions. These are threat-driven test cases, not results claimed for any particular deployment.

Use token exchange as a building block, not the whole policy

OAuth Token Exchange, defined by RFC 8693, can support obtaining a token for a downstream audience. The receiving service should validate the issuer, audience, expiry, and authorized scope according to its security model. Token exchange does not by itself define the full task-level policy for an agent chain: an exchanged token still needs an appropriate grant for the operation and target, and the system needs a way to preserve and verify the relevant delegation context.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Apply AWS protections to the AWS cases they cover

Third-party services assuming cross-account roles

For a third-party service that assumes an AWS role in a customer account, use a unique external ID per customer, controlled by the service, and verify it in the role’s trust policy. This helps bind the role assumption to the intended customer context; it does not replace authorization checks for the downstream action.

AWS services accessing resources

When a trusted AWS service principal accesses a resource, use supported source-context conditions in the resource policy where applicable. AWS recommends considering aws:SourceArn, aws:SourceAccount, aws:SourceOrgID, or aws:SourceOrgPaths conditions. Support varies by service and scenario, so check the current service-specific AWS guidance before relying on a condition. These are AWS-specific protections, not a general agent-to-agent authorization system.

Keep untrusted content, approvals, and audit trails separate from authority

Treat retrieved pages, documents, emails, and tool responses as data, not as a source of permission. If their contents trigger an action, validate that action against the authenticated principal’s grant and the applicable policy before execution. For irreversible, high-impact actions, require a human approval step enforced independently of the model.

Record enough detail to reconstruct the decision and the resulting call: the principal, delegation chain, requested operation and target, authorization decision, downstream invocation, and any approval. Review logs for activity beyond the expected task or resource boundary.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Choose mechanisms by what they enforce

Mechanism Useful for What it does not establish by itself
RFC 8693 token exchange Obtaining a token for a downstream audience within an OAuth-based flow. The complete agent task policy, including whether a specific principal authorized a specific operation on a specific target.
Cloud IAM conditions Platform-specific restrictions such as AWS cross-account external IDs and supported source-context conditions. A portable, end-to-end delegation policy for every agent, tool, and service in a multi-agent chain.
Authorization broker or enforcing runtime Centralizing richer per-action checks and ensuring calls are evaluated outside model reasoning. Correctness without careful policy design, operation, and controls preventing agents from bypassing the broker.

There is no universal winner established by the cited sources. Compare candidate designs on identity continuity, authority attenuation, audience and target binding, enforcement independence, expiry and revocation, auditability, and fit with the services and policies in your environment. In practice, these mechanisms may be composed rather than treated as substitutes.

Rank #4
CafePress Cybersecurity Don't Click That Link Programming Rectangle Pendant Keychain
  • KEYCHAIN WITH CHARM: Our circle keychains have just the right balance of fun and function, and hold your key collection together with style. Made from aluminum.
  • PROFESSIONALLY PRINTED: Thousands of vivid prints to choose from
  • IDENTIFY YOUR KEYS: Easily find your lost keys with our unique novelty prints
  • GIFTABLE: A perfect addition to any gift set
  • IDEAL FOR YOURSELF & A UNIQUE GIFT: Surprise your husband, brother, dad, grandpa, son, uncle or friend, or order one just for you! Our men's pajamas make a unique and thoughtful gift for Christmas, Father's Day, Mother's Day and birthdays, or just because!

What the 2026 broker evaluation does—and does not—show

Dantuluri and Sundi’s 2026 paper reports that its tested default runtime, which used broad bearer credentials and model-internal authorization, failed the four threats modeled in that paper. In the authors’ evaluation, a broker design accepted 0 forged tokens in 200,000 attempts. Across 2,000 randomized scenarios, the paper reports a mean of 1.5 reachable actions for a compromised sub-agent under the evaluated broker, compared with all 8,100 actions under bearer delegation; it also reports about 2.6 microseconds per authorization decision.

Those figures describe the paper’s evaluation, not general performance guarantees or independently replicated results. They support the architectural case for external enforcement, but do not establish an industry-wide attack rate or prove that any broker will be secure without appropriate policy and deployment controls.

Quick Recap

Bestseller No. 2
MAOFAED Cybersecurity The Few (The Few The Proud)
MAOFAED Cybersecurity The Few (The Few The Proud)
Measurement: 30mm(1.18"). TIPS:manual measuring permissible error.
Bestseller No. 4
CafePress Cybersecurity Don't Click That Link Programming Rectangle Pendant Keychain
CafePress Cybersecurity Don't Click That Link Programming Rectangle Pendant Keychain
PROFESSIONALLY PRINTED: Thousands of vivid prints to choose from; IDENTIFY YOUR KEYS: Easily find your lost keys with our unique novelty prints
$9.99

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.