InfoSec — AppSec & Security Engineering
Owner: AppSec or security engineering — whoever owns your SDLC security gate
What can be reached and what happens when someone abuses it — the actual blast radius of a compromised prompt, key, or session.
- No tool allowlist — the agent can call anything a session with its credentials could call, not a scoped subset
- No answer for what a compromised or malicious prompt could make the agent do downstream
- Secrets or credentials reachable from the same context window the model reads untrusted content in