发表机构
Bluebear Security(蓝熊安全公司)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
该研究针对AI编码智能体中授权与权限的持续差距,提出智能体姿态漏洞(APV)的概念,区分其与相关风险,提供定义、模式、生命周期等内容,为相关安全管理提供可操作框架。
AI 中文摘要
现有指导将过度自主性、过度权限、任务绑定授权薄弱以及智能体控制不足确定为重要风险。控制框架也描述了约束、授权、观测、验证和响应智能体活动的能力。然而,安全项目仍需要一种方法来管理跨越组件且超出任何单个事件的持续部署实例。我们提出智能体姿态漏洞(Agentic Posture Vulnerability, APV)作为一种任务条件型漏洞管理抽象:用于组合智能体控制暴露的持久记录。一种姿态可能在不同任务中产生不同的运行时表现;APV将这些表现与不变姿态关联起来,并保持开放状态,直到权限被缩小、添加了缺失的控制措施、风险被接受或关闭得到验证。APV并非作为一种新的根本原因风险类别提出;它将现有的过度自主性、授权和控制组合弱点进行了可操作化。我们将APV与CVE可寻址的产品缺陷、OWASP过度自主性、智能体基线控制结果以及运行时授权-执行差距区分开来。随后,我们提供了一个现场示例、阈值定义、六种常见APV模式、漏洞生命周期、最小记录、控制与关闭矩阵、工具含义以及可测试的研究议程。
英文摘要
Existing guidance identifies excessive agency, excessive permission, weak task-bound authorization, and inadequate agent controls as important risks. Control frameworks also describe capabilities for constraining, authorizing, observing, validating, and responding to agent activity. Yet security programs still need a way to manage persistent deployed instances that span components and outlive any one event. We propose the agentic posture vulnerability (APV) as a task-conditioned vulnerability-management abstraction: a durable record for a composed agent-control exposure. One posture may produce different runtime manifestations across tasks; APV links those manifestations to the invariant posture and remains open until authority is narrowed, a missing control is added, risk is accepted, or closure is verified. APV is not proposed as a new root-cause class of risk; it operationalizes existing excessive-agency, authorization, and control-composition weaknesses. We distinguish APVs from CVE-addressable product defects, OWASP Excessive Agency, Agent Baseline control outcomes, and the runtime authorization-execution gap. We then provide a field vignette, a thresholded definition, six recurring APV patterns, a vulnerability lifecycle, a minimum record, a control-and-closure matrix, tooling implications, and a testable research agenda.