CONCEPT Cited by 4 sources
Confused deputy problem¶
The confused deputy problem occurs when a trusted intermediary (the "deputy") is tricked into misusing its legitimate authority on behalf of an attacker who lacks that authority directly. The deputy acts within its permissions but performs an action it was never asked to perform by its legitimate principal.
Classic formulation¶
Originally described in capability-based security: a compiler service with write access to billing records was tricked by a user (who lacked billing access) into overwriting billing data, because the compiler ran with its own elevated privileges regardless of the requester's intent.
In AI agent systems¶
AI agents are a modern instantiation of the confused deputy. An agent running on valid credentials can perform any action its identity allows. When an attacker plants instructions in data the agent processes (indirect prompt injection), the agent may execute those instructions using its legitimate permissions — it becomes a confused deputy executing attacker-directed actions under its own authority.
The two gaps that compose into this attack:
- Prompt injection — the agent can't reliably distinguish instructions from data.
- Purpose-blind authorization — identity-based access control sees who is acting but not why, so it doesn't object when the agent performs an authorized action for the wrong reason.
Mitigation¶
- concepts/fine-grained-authorization — binds the agent session to a declared purpose so out-of-scope actions are denied even when identity allows them.
- patterns/tool-surface-minimization — static tool removal reduces the deputy's capabilities entirely.
- concepts/least-privileged-access — narrows identity-level permissions.
Seen in¶
- sources/2026-09-24-zalando-agentic-platform-open-sourcing-the-agentic-identity-broker
— the structural confused-deputy defense: keep the provider token out
of the deputy. Zalando's Agentic
Identity Broker + agentgateway gate ensures the
agent (the deputy) never receives a provider token — the token
exchange happens at the gateway and the credential "returns only to the
gateway," which swaps the
Authorizationheader before forwarding. A compromised/prompt-injected agent thus cannot leak or replay a provider credential it never held. Fine-grained per-tool-call authorization is layered via OPA/ExtProc so the deputy's actions are also purpose-checked, not just its identity — the out-of-band enforcement this page points to. - sources/2026-09-28-redpanda-your-ai-kill-switch-is-in-the-wrong-place — names the confused-deputy shape the business-context gap: an agent's sandbox / network allowlist / scoped API key controls what it can reach, not whether an action is right for the task. The canonical example — "deleting 100 abandoned test databases… retiring a deprecated production database… deleting one active production database… the actions seem identical, but the APIs called are the same. The keys are impossible to distinguish at the call site. What changes is the business context" — is the confused deputy stated at the operations altitude. Redpanda's fix is the same one this page points to: an out-of-band boundary that judges who asked, what task, why before allowing the action, deny-by-default.
- sources/2026-08-31-redpanda-corebreak-proves-agent-guardrails-need-to-live-outside-the-a-6ef5e77e — the CoreBreak class turns the agent into a confused deputy by forging the deputy's output (a tool call or approval injected into the message history) rather than by prompt-injecting its input. The fix is the same one this page points to: authorize at execution time against a resource-owned policy ceiling so a forged call "can do at most what a legitimate call could."
- sources/2026-07-23-databricks-intent-based-authorization-omnigent — Databricks demonstrates a data-quality agent tricked (via indirect prompt injection in table data) into granting external users table access — an action it's permitted to perform but wasn't asked to. Intent-based authorization closes this gap.
Related¶
- concepts/prompt-injection — the injection vector
- concepts/fine-grained-authorization — the purpose-binding solution
- concepts/least-privileged-access — identity-layer mitigation
- systems/omnigent — reference implementation of the fix