AI Agent Authentication and Authorization (IETF Internet-Draft)

(datatracker.ietf.org)

4 points | by jhgaylor 19 hours ago ago

3 comments

  • jhgaylor 19 hours ago ago

    This is at the bottom of section 8

    > The Large Language Model MUST NOT have access to an agent's credentials or to credentials that may be needed to access tools and services. This prevents the Large Language Model from using, exposing, or being manipulated via prompt injection into disclosing the credentials.

    I knew this but I just went ahead doing it wrong anyway. As a stop gap I gave all my secrets handles so the LLM and I could discuss them but I am just pretending that my agent is trustworthy. We have some big names here so hopefully there is better tooling in our future.

  • ninjalanternshk 10 hours ago ago

    Yes please. This nonsense of agents controlling browsers where the user has logged into sites as themselves needs to die before it takes off.