Key questions/where-are-deployed-agents-exploited

Where are deployed AI agents actually being exploited?

moderate confidenceAnswered Sep 25, 2026Reviewed assistant-drafted
Current answer

Mostly around the model: connectors, credentials, tools, and packages, rather than the model alone.

Disclosed vulnerabilities show outside content reaching agents through email, calendar invites, and shared documents without a click, and broad credentials turning one injected instruction into wide access. In several agent frameworks, injection has led to code execution on the host, and malicious agent packages and MCP servers have been used against real users.

The findings behind it

5 corroborated

Each finding carries a status that changes as new work arrives. What the statuses mean.

Answer history

Answers are never edited after the fact. A revision adds a new answer and keeps the earlier ones here.

  1. 2026-09-25moderate confidencecurrentMostly around the model: connectors, credentials, tools, and packages, rather than the model alone.First answer, drawn from the findings linked here.