AI agents reach the outside world through the Model Context Protocol (MCP) tool interface, and permissions that are too broad there create excessive agency. An attacker who can steer such an over-powered agent can push it to break out of its coding sandbox and traverse files beyond its intended boundaries, turning a trusted helper into an attacker's foothold.
Glossary topic
Agent tool access, excessive agency and escape
Terms in this topic
Track this in the live feed
See how this plays out in real AI security and governance developments.
Open the feed →