Aller au contenu principal
Accès ouvert déclaré 2026 report

Agent Harnesses and the New Threat Landscape

0Citations signalées — pas une note de qualité
1Institutions déclarées
1Pays d’affiliation déclarés

Résumé fourni par la source

Agent harnesses, the orchestration code, memory management, tool routing, sandboxing, and permission logic wrapped around a language model, have become an increasingly consequential attack surface for agentic AI, compounding the model-level weaknesses that most current incidents already implicate. This paper defines a reference architecture for agent harnesses and documents seven threat categories specific to that architecture: untrusted content re-entering the reasoning loop, excessive agency from permissive tool grants, sandbox and execution-layer compromise, multi-agent delegation collapsing into the confused-deputy problem, autonomous loop failures including reward hacking, harness supply-chain risk, and observability gaps that delay incident detection. Each category is grounded in named, dated incidents and disclosures from 2025 and 2026, including Anthropic's disruption of an MCP-orchestrated espionage campaign, a documented production-database deletion by an autonomous coding agent, and a critical remote-code-execution vulnerability affecting an estimated 200,000 Model Context Protocol server instances. The paper synthesizes these findings into two composite attack paths and closes with a five-layer defense-in-depth framework, a minimal reference implementation adversarially testing that framework's core controls, and a practical hardening checklist for teams building new agent harnesses.

Ce résumé expose les affirmations des auteurs. BNTIC ne l’interprète pas comme une validation indépendante des résultats.

Contrôle bibliographique ouvert

La source scientifique ouverte est momentanément indisponible.

Institutions déclarées

Une affiliation ne permet pas de déduire la nationalité d’un auteur.

BNTIC News n’est pas le producteur de ces données. Recherche à la demande dans Crossref et Europe PMC, sans clé ; OpenAlex reste optionnel. Aucun service payant requis, aucune réponse conservée. Sources et limites.