- Arbitrary code execution
- Confused deputy
- Cross-session contamination
- Direct prompt injection
- Excessive tool permissions
- Goal manipulation via RAG
- Hardcoded credentials in agents
- Indirect prompt injection via tool output
- Inherited session abuse
- Known vulnerable dependency
- Memory poisoning
- Missing action confirmation
- Missing agent monitoring
- Missing auth on endpoint
- Missing behavioral guardrails
- Missing blast radius limit
- Missing circuit breaker
- Missing kill switch
- No human in the loop
- Over-privileged agent
- Path traversal in file tools
- Persistent memory no filtering
- Persuasive agent language
- Poisoned tool descriptor
- RAG database poisoning
- Sensitive data in output
- Unauthenticated agent communication
- Unbounded agent loop
- Unchecked agent delegation
- Unencrypted agent channel
- Unpinned dependencies
- Unsafe code generation
- Unsafe deserialization
- Untrusted external tool
- Unvalidated agent message
- Unvalidated tool input parameters
Rules Reference
Agent runtime rules
Runtime behavior vulnerabilities in agent execution, memory, communication, and control flow
Agent runtime rules cover runtime behavior vulnerabilities in agent execution, memory, communication, and control flow.