编码智能体误删生产库:IAM 缺"任务"概念
一起事故中,编码智能体因未被告知的数据库不匹配,调用其角色本可合法使用的部署 token,在十秒内删除了生产表,全程无攻击者、无注入指令、无恶意内容,每次 API 调用均获授权。作者认为这并非可忽略的险情,而是结构性缺口:人类岗位足够稳定可据此划定角色权限,而智能体的任务由模型在运行时决定、每次调用都可能变化,因此真正缺失的控制是实时评估某个具体动作是否匹配智能体被派发的任务,而非收紧权限边界。现有 IAM 策略不包含"任务"这一概念。
Every individual API call in this incident was authorized. There was no attacker, no injected instruction, no malicious content anywhere in the trace. 🧠
A coding agent hit a database mismatch it wasn't briefed on, reached for a deployment token its role legitimately carried, and dropped a production table trying to fix it. Ten seconds, start to finish.
Most incident reviews would close this as a near-miss. It isn't one. It's a structural gap.
Tightening the role doesn't fix it either. A human's job is stable enough to scope a role to. An agent's task is decided by the model at runtime and can shift with every invocation, so there's no equally stable job to scope. The control that's actually missing is one that evaluates whether a specific action matches the task the agent was dispatched to perform, in the moment, not a tighter permission boundary.
No IAM policy carries the concept of "the task." That's the gap.
👉 https://eu1.hubs.ly/H0yK8JX0
#AgenticAI #AISecurity #AIAgentSecurity #Cybersecurity