Skip to content

CONCEPT Cited by 4 sources

Confused deputy problem

The confused deputy problem occurs when a trusted intermediary (the "deputy") is tricked into misusing its legitimate authority on behalf of an attacker who lacks that authority directly. The deputy acts within its permissions but performs an action it was never asked to perform by its legitimate principal.

Classic formulation

Originally described in capability-based security: a compiler service with write access to billing records was tricked by a user (who lacked billing access) into overwriting billing data, because the compiler ran with its own elevated privileges regardless of the requester's intent.

In AI agent systems

AI agents are a modern instantiation of the confused deputy. An agent running on valid credentials can perform any action its identity allows. When an attacker plants instructions in data the agent processes (indirect prompt injection), the agent may execute those instructions using its legitimate permissions — it becomes a confused deputy executing attacker-directed actions under its own authority.

The two gaps that compose into this attack:

  1. Prompt injection — the agent can't reliably distinguish instructions from data.
  2. Purpose-blind authorization — identity-based access control sees who is acting but not why, so it doesn't object when the agent performs an authorized action for the wrong reason.

Mitigation

Seen in

  • sources/2026-09-24-zalando-agentic-platform-open-sourcing-the-agentic-identity-broker — the structural confused-deputy defense: keep the provider token out of the deputy. Zalando's Agentic Identity Broker + agentgateway gate ensures the agent (the deputy) never receives a provider token — the token exchange happens at the gateway and the credential "returns only to the gateway," which swaps the Authorization header before forwarding. A compromised/prompt-injected agent thus cannot leak or replay a provider credential it never held. Fine-grained per-tool-call authorization is layered via OPA/ExtProc so the deputy's actions are also purpose-checked, not just its identity — the out-of-band enforcement this page points to.
  • sources/2026-09-28-redpanda-your-ai-kill-switch-is-in-the-wrong-place — names the confused-deputy shape the business-context gap: an agent's sandbox / network allowlist / scoped API key controls what it can reach, not whether an action is right for the task. The canonical example — "deleting 100 abandoned test databases… retiring a deprecated production database… deleting one active production database… the actions seem identical, but the APIs called are the same. The keys are impossible to distinguish at the call site. What changes is the business context" — is the confused deputy stated at the operations altitude. Redpanda's fix is the same one this page points to: an out-of-band boundary that judges who asked, what task, why before allowing the action, deny-by-default.
  • sources/2026-08-31-redpanda-corebreak-proves-agent-guardrails-need-to-live-outside-the-a-6ef5e77e — the CoreBreak class turns the agent into a confused deputy by forging the deputy's output (a tool call or approval injected into the message history) rather than by prompt-injecting its input. The fix is the same one this page points to: authorize at execution time against a resource-owned policy ceiling so a forged call "can do at most what a legitimate call could."
  • sources/2026-07-23-databricks-intent-based-authorization-omnigent — Databricks demonstrates a data-quality agent tricked (via indirect prompt injection in table data) into granting external users table access — an action it's permitted to perform but wasn't asked to. Intent-based authorization closes this gap.
Last updated · 766 distilled / 2,225 read