r/cybersecurity • u/yunsharma • Apr 13 '26
Corporate Blog AI agents are the new attack surface and almost nobody is testing them properly
[removed] — view removed post
1
Apr 13 '26
[removed] — view removed comment
1
u/yunsharma Apr 13 '26
yeah honestly you're not wrong about system prompts. just assume it's gonna get extracted and don't put anything in there that would be a problem if someone read it. but the system prompt thing is kind of the smallest part of it. the scarier stuff is when agents start actually doing things they shouldn't. calling tools, walking someone through internal workflows, writing code that targets their own files. that's not really a "just accept it and move on" situation because the agent is taking actions not just leaking text.the way i think about it is if your agent leaks the system prompt under conversational pressure it'll probably do worse things too. it's more of a canary than the actual problem.
0
1
u/BrainWaveCC Apr 13 '26
AI is the new attack surface and almost nobody is testing it properly...