Confused deputy
A well-documented computer security failure, named by Norman Hardy in 1988, in which a system with legitimate authority is tricked, through an otherwise normal and correctly authenticated request, into misusing that authority on an attacker's behalf, because it cannot distinguish a legitimate request from a malicious one that arrives through an otherwise-trusted channel. The reason authentication alone never fully closes T12; a confused-deputy attack does not require breaking the authentication scheme, only manipulating what an already-trusted party is persuaded to do. Named in the CSA's protocol-layer findings as a risk all tool-calling agents share. (see Topic 5.6)
Defined in 2 GAGE programs, which carry 9 distinct definitions of it. The wording above is taught in Agentic AI Governance: Applied Mastery.
How each discipline defines it
The same term does different work depending on who is using it. These are the definitions as each program teaches them, unedited.
A well-documented computer security failure, named by Norman Hardy in 1988, in which a system with legitimate authority is tricked, through an otherwise normal and correctly authenticated request, into misusing that authority on an attacker's behalf, because it cannot distinguish a legitimate request from a malicious one that arrives through an otherwise-trusted channel. The reason authentication alone never fully closes T12; a confused-deputy attack does not require breaking the authentication scheme, only manipulating what an already-trusted party is persuaded to do. Named in the CSA's protocol-layer findings as a risk all tool-calling agents share. (see Topic 5.6)
A privileged program (such as an agent holding your credentials) tricked by a less-privileged caller (an attacker's planted text) into misusing its authority on the caller's behalf. First described by Norm Hardy (1988); re-emerging as a high-severity AI agent pattern (Cloud Security Alliance, 2025 to 2026).
A general security term for a system that has legitimate authority to act but is tricked, by an untrusted party, into using that authority on the tricked party's behalf. The GitHub MCP case is a concrete instance of this pattern applied to an AI agent's tool access. (Owned in threat-taxonomy depth by (see Topic 5.6).)
A program that holds more authority than the party currently directing it, and that can be tricked into using that authority on an attacker's behalf because it cannot distinguish a legitimate instruction from an injected one.
A threat pattern, named in the CSA Addendum's MCP annex, where a component with legitimate high privilege is tricked, through untrusted input it trusts too readily, into acting on behalf of a request it should not have honored; a direct illustration of what happens when no isolation boundary exists between tainted input and a privileged action (see Topic 5.6).
Where it is taught
The exact lessons this term appears in. The first 7 topics of every program are free with a free account.
- Agent-Specific Security Concerns and Mitigation · AI Security Fundamentals, AI Literacy & Professional Conduct
- The Parts That Make an Agent Act · The Agent, Deconstructed, Agentic AI Governance: Applied Mastery
- Protocol-Layer Threats · Technical Controls and Threat Modeling, Agentic AI Governance: Applied Mastery
- Taint Tracing · Technical Controls and Threat Modeling, Agentic AI Governance: Applied Mastery
- Red Teaming an Agent Starts With Its Use Case, Not a Generic Checklist · Testing and Red-Teaming, Agentic AI Governance: Applied Mastery
- Probing Data Boundaries · Testing and Red-Teaming, Agentic AI Governance: Applied Mastery
- Watching an Agent Work · Rollout, Monitoring, and Incident Response, Agentic AI Governance: Applied Mastery
- The Enterprise Control Plane · Rollout, Monitoring, and Incident Response, Agentic AI Governance: Applied Mastery
- Multi-Agent Controls · Multi-Agent Governance, Agentic AI Governance: Applied Mastery
Terms it appears with
Not an alphabetical neighbourhood: these are the terms taught in the same lessons, ranked by how often they appear together.