The Agent Threat Model

The map of how agents get attacked: one token stream that cannot tell instructions from data, an agent that turns that confusion into actions, the lethal trifecta that makes it exfiltration, and the OWASP taxonomies that name the rest.

Content current as of 2026-09.

Lessons

  1. One token stream, and now it has hands
  2. The lethal trifecta
  3. The OWASP landscape: two lists you will be asked about
  4. EchoLeak, end to end
  5. Threat-modelling a new agent design