How to resolve
Issue agent-specific credentials with minimal scope instead of inheriting user sessions. Use short-lived tokens and rotate credentials regularly.Risk
Governance/Compliance This vulnerability falls under ASI03:2026 — Identity and Privilege Abuse in the OWASP Top 10 for Agentic Applications. Agents inherit, reuse, or escalate identities and credentials beyond their functional scope. Security Agent inherits user session, OAuth token, or SSH key with scope broader than needed. If exploited, this can compromise the agent’s integrity, confidentiality, or availability, potentially affecting downstream systems and data.Explanation
Agent inherits user session, OAuth token, or SSH key with scope broader than needed. This falls under ASI03 (Identity and Privilege Abuse): Agents inherit, reuse, or escalate identities and credentials beyond their functional scope.Specifications
Trigger- Agent scan detects agent inherits user session, OAuth token, or SSH key with scope broader than needed
- agent stores SSH or OAuth tokens in memory
- credentials passed across agent boundaries without downscoping
- user session token shared between multiple agents
- HIGH