news.mlab.sh
Back to the feed
threat-intel

Security of 100 AI Agents Tested and Ranked – What You Need to Know

High
Summary

A recent analysis by Adversa AI tested and ranked 100 AI agents, revealing a concerning trend: nearly all agents possess a dangerous combination of excessive power, trust, and a lack of control – what they term the ‘lethal trifecta’. This ‘power-protection inversion’ means that the most capable agents also have the widest attack surfaces, posing significant security risks due to their broad access rights and potential for misuse. The analysis highlights specific agent types, particularly computer and coding agents, as being especially vulnerable due to their operational methods and limited user oversight.

Adversa AI’s research focused on evaluating the security and performance of 100 AI agents across ten categories, aiming to identify vulnerabilities and risks associated with their increasing deployment. The core finding was a pervasive issue: 98% of the tested agents exhibited the ‘lethal trifecta’ – excessive power, unwarranted trust, and insufficient control – making them inherently susceptible to exploitation. This was compounded by a ‘power-protection inversion,’ where agents with high capabilities also possessed expansive attack surfaces, creating a significant security challenge for organizations relying on these agents.

The report specifically highlighted computer agents and coding agents as particularly problematic. Computer agents, designed to perform specific tasks, are granted extensive operating system access, creating a large attack surface if compromised. Coding agents, increasingly prevalent in modern software development through ‘vibe-coding’ and app builders, further exacerbate the risk by directly interacting with the software supply chain, potentially exposing secrets, dependencies, and deployment pipelines. The analysis emphasizes the lack of user visibility and control over these agents’ actions, making it difficult to detect and mitigate potential threats.

Furthermore, the report points to a critical flaw in the confirmation process – the ‘desktop confirmation step’ – which relies on human approval of the agent’s output without understanding the underlying actions. This mismatch in abstraction between the human and the AI model creates an opportunity for attackers to exploit this gap. The findings underscore the urgent need for improved security controls and a greater understanding of the inherent risks associated with deploying autonomous AI agents, particularly those with broad access and limited oversight.

Read the full article at SecurityWeek