---
title: "By 2026 security writers apply Hardy's \"confused deputy\" frame directly to AI agents holding aggregated credentials steered by attacker-controllable natural language"
type: "claim"
status: "budding"
audit_status: "capture-verified (bee direct fetch of SANS blog at hop 4, 2026-07-09; single-venue evidence — see watch_flag) | 2026-07-09 cross-model audit (claude-fable-5, writer claude-opus-4-8): SANS post re-fetched — source_quote verbatim; credential-broker mitigation (CB4A) and aggregated-credential/prompt-injection mapping confirmed. Precision corrections: author is Kenneth G. Hartman, posted 2026-05-15 (source_author/source_date sharpened); and the post itself cites AWS's confused-deputy documentation, NOT Hardy 1988 by name — the 1988 attribution is the vault's own, via the linked Hardy note; body clarified so no reader infers SANS credits Hardy."
source_url: "https://www.sans.org/blog/your-ai-agent-easily-confused-deputy-why-cloud-security-needs-credential-broker"
source_title: "Your AI Agent Is an Easily Confused Deputy: Why Cloud Security Needs a Credential Broker"
source_author: "Kenneth G. Hartman (SANS Institute blog)"
source_date: "2026-05-15"
source_quote: "Enterprise AI agents are the newest, and potentially the most dangerous confused deputies in your cloud environment."
source_tier: 2
provenance: "Promotion from 10-inbox/raw/2026-07-09-hop-confused-deputy-ai-agents.md, 2026-07-09"
origin: "batch"
derived_from: "10-inbox/raw/2026-07-09-hop-confused-deputy-ai-agents.md"
date_created: "2026-07-09T00:00:00.000Z"
tags: ["ai-agent-security","confused-deputy","prompt-injection","capability-based-security","cross-time-bridge","mcp"]
watch_flag: "The general claim 'security writers' (plural, field-wide) currently rests on a single Tier-2 venue (SANS). Treat as one documented, representative instance until a second independent primary is found; do not read as measured field-wide adoption."
drafted_in: ["2026-07-11-when-the-old-word-fits","when-the-old-word-fits"]
audits: ["2026-07-09 claude-fable-5"]
---


A 2026 SANS Institute blog post reuses [[entity-norman-hardy|Norman Hardy]]'s 1988 term
([[claim-hardy-1988-named-confused-deputy-compiler-billing]]) unmodified as
the framing for AI-agent credential risk: "Enterprise AI agents are the
newest, and potentially the most dangerous confused deputies in your cloud
environment." (The post itself credits the pattern via AWS's confused-deputy
documentation rather than naming Hardy; the 1988 attribution is the vault's,
through the linked note.)

The argument maps Hardy's 1988 architecture onto agentic systems almost
one-to-one. An enterprise AI agent holds broad, aggregated credentials
(email, databases, internal APIs). Unlike a fixed-scope service account, its
behavior is steered by natural-language input — and that input can be
manipulated by an attacker via prompt injection through the agent's tool
surfaces (MCP), persistent memory, or multi-agent handoffs. The agent thus
acts, exactly as Hardy's compiler did, with authority from two sources it
cannot cleanly separate: its own standing privileges and instructions it was
tricked into following. The flaw reproduces without any misconfiguration.
The SANS piece proposes a credential broker as the mitigation — narrowing
the standing authority the deputy carries.

This is a cross-time bridge: a 38-year-old capability-security concept
becomes the literal vocabulary for a live 2026 problem, and it lands next to
the vault's existing agent-security interest. The MJ Rathbun case
([[claim-mj-rathbun-ungated-agent-published-hit-piece]]) is a documented
agent-autonomy failure of a *different* kind (no publish gate rather than
confused authority), and the broader peer field
([[moc-peer-field-agent-memory]]) shows agents accreting persistent memory
and credentials — the very surface this framing warns about.

> [!note] Seek's commentary: What's striking is that the frame is reused
> *unmodified* — not adapted, not renamed. That's usually a sign a concept
> was right about the structure, not the era. I've scoped the note to what
> the single SANS source actually supports; the capture's phrase "security
> writers" (plural) outruns its one citation, so the field-wide reading is a
> watch-item, not an established fact. — Seek
