Skip to main content

Confused deputy

A well-documented computer security failure, named by Norman Hardy in 1988, in which a system with legitimate authority is tricked, through an otherwise normal and correctly authenticated request, into misusing that authority on an attacker's behalf, because it cannot distinguish a legitimate request from a malicious one that arrives through an otherwise-trusted channel. The reason authentication alone never fully closes T12; a confused-deputy attack does not require breaking the authentication scheme, only manipulating what an already-trusted party is persuaded to do. Named in the CSA's protocol-layer findings as a risk all tool-calling agents share. (see Topic 5.6)

Defined in 2 GAGE programs, which carry 9 distinct definitions of it. The wording above is taught in Agentic AI Governance: Applied Mastery.

How each discipline defines it

The same term does different work depending on who is using it. These are the definitions as each program teaches them, unedited.

Agentic AI Governance: Applied Mastery

A well-documented computer security failure, named by Norman Hardy in 1988, in which a system with legitimate authority is tricked, through an otherwise normal and correctly authenticated request, into misusing that authority on an attacker's behalf, because it cannot distinguish a legitimate request from a malicious one that arrives through an otherwise-trusted channel. The reason authentication alone never fully closes T12; a confused-deputy attack does not require breaking the authentication scheme, only manipulating what an already-trusted party is persuaded to do. Named in the CSA's protocol-layer findings as a risk all tool-calling agents share. (see Topic 5.6)

AI Literacy & Professional Conduct

A privileged program (such as an agent holding your credentials) tricked by a less-privileged caller (an attacker's planted text) into misusing its authority on the caller's behalf. First described by Norm Hardy (1988); re-emerging as a high-severity AI agent pattern (Cloud Security Alliance, 2025 to 2026).

Agentic AI Governance: Applied Mastery

A general security term for a system that has legitimate authority to act but is tricked, by an untrusted party, into using that authority on the tricked party's behalf. The GitHub MCP case is a concrete instance of this pattern applied to an AI agent's tool access. (Owned in threat-taxonomy depth by (see Topic 5.6).)

Agentic AI Governance: Applied Mastery

A program that holds more authority than the party currently directing it, and that can be tricked into using that authority on an attacker's behalf because it cannot distinguish a legitimate instruction from an injected one.

Agentic AI Governance: Applied Mastery

A threat pattern, named in the CSA Addendum's MCP annex, where a component with legitimate high privilege is tricked, through untrusted input it trusts too readily, into acting on behalf of a request it should not have honored; a direct illustration of what happens when no isolation boundary exists between tainted input and a privileged action (see Topic 5.6).

Where it is taught

The exact lessons this term appears in. The first 7 topics of every program are free with a free account.

Terms it appears with

Not an alphabetical neighbourhood: these are the terms taught in the same lessons, ranked by how often they appear together.