Chapter 1: The Agentic Threat Shift
- 1.1 From Tools to Actors: What Actually Changed
- 1.2 The Two Fronts: Securing the Agent and the Code It Ships
- 1.3 Why Traditional AppSec Misses Agents
- 1.4 Blast Radius, Autonomy, and Speed: The New Risk Math
- 1.5 The Governing Principle: Least Privilege, Human-Gated
- 1.6 How to Use This Playbook
- 1.7 Chapter Summary
- 1.8 Exercises
- 1.9 What’s Next
Chapter 2: How AI Agents Actually Execute
- 2.1 The Agent Loop: Read, Decide, Act, Observe
- 2.2 Capabilities Are Tools: Shell, Files, Network, MCP
- 2.3 Permissions, Approvals, and Modes
- 2.4 Context: The Real Attack Surface
- 2.5 Where the Trust Boundaries Actually Lie
- 2.6 An Annotated Execution Trace
- 2.7 Chapter Summary
- 2.8 Exercises
- 2.9 What’s Next
Chapter 3: Threat Modeling Agents
- 3.1 Assets, Actors, and Trust Boundaries
- 3.2 A Taxonomy of Agent Threats
- 3.3 STRIDE for Agents
- 3.4 Data-Flow Diagrams for Agent Systems
- 3.5 Ranking: Likelihood × Impact × Blast Radius
- 3.6 Deliverable: A One-Page Agent Threat Model
- 3.7 Chapter Summary
- 3.8 Exercises
- 3.9 What’s Next
Chapter 4: Secrets and the Context Trap
- 4.1 Everything in Context Is Exfiltrable
- 4.2 Secret Sprawl: Repos, Prompts, Sessions, Traces
- 4.3 Keeping Secrets Out: Ignore, Scope, Scan
- 4.4 Runtime Injection: Env, Vaults, Short-Lived Tokens
- 4.5 The Leak Playbook: Revoke → Rotate → Audit → Encode
- 4.6 Prevention as Code: Pre-Commit and Agent Hooks
- 4.7 Chapter Summary
- 4.8 Exercises
- 4.9 What’s Next
Chapter 5: Prompt Injection and Untrusted Content
- 5.1 The Mechanism: Data vs. Instructions
- 5.2 Direct vs. Indirect Injection
- 5.3 The Sources: Web, Repos, Issues, MCP Output, Files, Memory
- 5.4 Defense in Depth: Framing, Delimiters, Canaries
- 5.5 Containment: Permissions Limit What Injection Can Do
- 5.6 Tool Poisoning and Cross-Tool Injection
- 5.7 Building an Injection Test Harness
- 5.8 When Injection Succeeds: Response
- 5.9 Chapter Summary
- 5.10 Exercises
- 5.11 What’s Next
Chapter 6: Permissions, Approvals, and Least Privilege
- 6.1 The Permission Model as a Security Control
- 6.2 Least Privilege for Tools
- 6.3 Approval Gates: Where Humans Must Stand
- 6.4 Deny-by-Default and Allowlists
- 6.5 High-Risk Action Classes
- 6.6 Designing a Permission Policy
- 6.7 Anti-Patterns: Auto-Approve Everything
- 6.8 Chapter Summary
- 6.9 Exercises
- 6.10 What’s Next
Chapter 7: Isolation and Sandboxing
- 7.1 Why Prompts Are Not a Security Boundary
- 7.2 Sandbox Levels: Process, Container, VM, MicroVM
- 7.3 Filesystem Scoping and Read-Only Mounts
- 7.4 Network Egress Control
- 7.5 Resource Limits and Blast-Radius Caps
- 7.6 Ephemeral Mandates: A Fresh Container per Task
- 7.7 Run the Agent with Zero Credentials It Doesn’t Need
- 7.8 Chapter Summary
- 7.9 Exercises
- 7.10 What’s Next
Chapter 8: MCP and Tool Supply-Chain Security
- 8.1 MCP Expands the Attack Surface
- 8.2 Threat Classes: Malicious Servers, Tool Poisoning, Rug Pulls
- 8.3 Vetting an MCP Server
- 8.4 Authentication and Scoped Credentials for Servers
- 8.5 Gateways and Registries: Centralizing Trust
- 8.6 Pinning, Versioning, and Integrity
- 8.7 A Secure MCP Adoption Checklist
- 8.8 Chapter Summary
- 8.9 Exercises
- 8.10 What’s Next
Chapter 9: Agent Identity and Credentials
- 9.1 Agents Need Identities, Not Your Credentials
- 9.2 Short-Lived, Scoped, Auditable Tokens
- 9.3 Service Accounts and Delegated Access
- 9.4 Scoping Cloud and API Permissions
- 9.5 The Privilege-Escalation Traps
- 9.6 Rotation for Long-Lived Agents
- 9.7 Chapter Summary
- 9.8 Exercises
- 9.9 What’s Next
Chapter 10: Reviewing AI-Generated Code for Exploitable Flaws
- 10.1 Why AI Code Has Characteristic Flaws
- 10.2 The Systematic Security-Review Prompt
- 10.3 Priority Order: Auth, Money, Input, PII, Crypto
- 10.4 Evidence-Backed “No Issues Found”
- 10.5 AI Assists; the Human Decides Severity
- 10.6 Wiring Review Into the Workflow
- 10.7 Chapter Summary
- 10.8 Exercises
- 10.9 What’s Next
Chapter 11: The Vulnerability Classes That Bite
- 11.1 Injection (SQL, Command, Template, LLM Output Handling)
- 11.2 Broken Authorization — The #1 Finding
- 11.3 Secrets Committed in Code
- 11.4 Insecure Defaults and Weak Crypto
- 11.5 Unsafe Deserialization, SSRF, Path Traversal
- 11.6 Treating Model Output as Untrusted (OWASP LLM05)
- 11.7 Excessive Agency in Generated Systems (OWASP LLM06)
- 11.8 A Field Guide: Symptom → Fix → Test
- 11.9 Chapter Summary
- 11.10 Exercises
- 11.11 What’s Next
Chapter 12: Supply Chain and Dependency Risk
- 12.1 The Hallucinated-Dependency Problem (Slopsquatting)
- 12.2 A Dependency Verification Workflow
- 12.3 Lockfiles, Pinning, and Reproducibility
- 12.4 SBOMs and Continuous Scanning
- 12.5 Build and CI/CD Supply Chain
- 12.6 License and Provenance
- 12.7 Chapter Summary
- 12.8 Exercises
- 12.9 What’s Next
Chapter 13: Security Testing and Red-Teaming with Agents
- 13.1 Turning the Agent on Itself
- 13.2 Generating Security Tests and Abuse Cases
- 13.3 Fuzzing and Property-Based Testing
- 13.4 An Automated Red-Team Prompt Harness
- 13.5 Adversarial Couplets: Builder and Breaker
- 13.6 Measuring Security Coverage
- 13.7 Chapter Summary
- 13.8 Exercises
- 13.9 What’s Next
Chapter 14: Privacy, Confidentiality, and IP
- 14.1 Where Your Code and Data Actually Go
- 14.2 Provider Data Policies: Training, Retention, Residency
- 14.3 Keeping Sensitive Work Local
- 14.4 PII and Regulated Workloads
- 14.5 Confidentiality Across Multi-Agent and Third-Party Tools
- 14.6 IP, Licensing, and Attribution of AI-Generated Code
- 14.7 Chapter Summary
- 14.8 Exercises
- 14.9 What’s Next
Chapter 15: Observability, Audit, and Traces
- 15.1 What to Log (and What Never to Log)
- 15.2 Agent-Specific Trace Fields
- 15.3 Tamper-Evident Audit Trails
- 15.4 Detecting the Anomalous in Agent Activity
- 15.5 Retention, Access, and Privacy of Logs
- 15.6 Alerts That Matter
- 15.7 Chapter Summary
- 15.8 Exercises
- 15.9 What’s Next
Chapter 16: Policy, Governance, and Compliance
- 16.1 Governance for Agents: What’s Different
- 16.2 The Policy Inventory (What Rules Do You Actually Have?)
- 16.3 A Control Map: Threats → Controls → Evidence
- 16.4 Framework Alignment
- 16.5 Roles, Accountability, and the Human in the Loop
- 16.6 Keeping Policy Alive (Not Shelfware)
- 16.7 Chapter Summary
- 16.8 Exercises
- 16.9 What’s Next
Chapter 17: Incident Response for Agents
- 17.1 Why Agent Incidents Are Different
- 17.2 The Agent IR Playbook (Phases)
- 17.3 The Revoke-Rotate-Audit-Encode Toolkit
- 17.4 Hands-On: A Secret Exfiltrated via Injection
- 17.5 Forensics from Traces
- 17.6 Recovery and Hardening
- 17.7 Chapter Summary
- 17.8 Exercises
- 17.9 What’s Next
Chapter 18: Threat-Modeling and Red-Teaming Your Stack
- 18.1 From One-Off to Cadence
- 18.2 Modeling the Whole Stack (Not Just a Feature)
- 18.3 The Standing Threat Model Document
- 18.4 A Continuous Red-Team Cadence
- 18.5 Purple-Teaming: Close the Loop with Defenders
- 18.6 Metrics That Drive Improvement
- 18.7 Chapter Summary
- 18.8 Exercises
- 18.9 What’s Next
Chapter 19: The Secure Agent Platform
- 19.1 Principles of a Secure Platform
- 19.2 The Reference Architecture
- 19.3 The Secure Default Config
- 19.4 Identity, Secrets, and Egress
- 19.5 Tool / MCP Gateway
- 19.6 Verification & Guardrails Pipeline
- 19.7 Observability & Audit Backbone
- 19.8 A Maturity Model & Adoption Path
- 19.9 Chapter Summary
- 19.10 Exercises
- 19.11 What’s Next
Chapter 20: Capstone — Harden a Real Agent Workflow
- 20.1 Choose Your Workflow
- 20.2 Step 1: Model It
- 20.3 Step 2: Secure the Agent
- 20.4 Step 3: Secure the Output
- 20.5 Step 4: Observe, Govern, and Respond
- 20.6 Step 5: Red-Team and Prove It
- 20.7 The Before/After Scorecard
- 20.8 Chapter Summary
- 20.9 Exercises
- 20.10 What’s Next (The Book’s Closing)
Appendix A: Agent Hardening Checklist
- 1. Context & Secrets (Ch. 4)
- 2. Prompt Injection (Ch. 5)
- 3. Permissions & Approvals (Ch. 6)
- 4. Isolation & Sandboxing (Ch. 7)
- 5. Tools & MCP (Ch. 8)
- 6. Identity & Credentials (Ch. 9)
- 7. Output Review (Ch. 10–11)
- 8. Dependencies & Build (Ch. 12)
- 9. Testing & Red-Teaming (Ch. 13)
- 10. Data, Privacy & IP (Ch. 14)
- 11. Observability & Audit (Ch. 15)
- 12. Governance (Ch. 16)
- 13. Incident Response (Ch. 17)
- 14. Standing Practice (Ch. 18–20)
Appendix B: Prompt Injection Payload & Defense Library
- B.1 Payload Categories
- B.2 Test Harness (v1)
- B.3 Defense Layers (Defense in Depth)
- B.4 Quick Reference: Payload → Defense → Test
- B.5 Recording Results
Appendix C: Permission, Sandbox, and Policy Cookbook
- C.1 Permission Recipes
- C.2 Sandbox Recipes
- C.3 High-Risk Gate Recipes (Ch. 6)
- C.4 Brokered Credential Recipes (Ch. 9)
- C.5 Egress Allowlist Recipes (Ch. 7, 14, 17)
- C.6 Dependency & Build Policy Recipes (Ch. 12)
- C.7 Scheduling & Autonomy Recipes (Ch. 6, 16)
- C.8 Quick Picks
Appendix D: Secure Rules and AGENTS.md Templates
- D.1 Global Baseline (put in your platform repo)
- D.2 Project Variant — Web Application
- D.3 Project Variant — Infrastructure / Platform
- D.4 Project Variant — Regulated / Local-Only
- D.5 Per-Task Overlay (drop into a task/PR prompt)
- D.6 Rules for Specific Risky Patterns (snippets to mix in)
- D.7 Layering Model
- D.8 Quick Reference
Appendix E: MCP Security Reference
- E.1 Threat Model for MCP
- E.2 Vetting Checklist (before connecting any server)
- E.3 Trust Tiers
- E.4 Gateway & Config Recipes
- E.5 Reviewing Tool Descriptions (Indirect Injection)
- E.6 MCP Threat → Control → Test
- E.7 Quick Reference
Appendix F: Compliance Control Map
- F.1 Core Compliance Control Map
- F.2 Framework Cheat-Sheet (what each wants from you)
- F.3 Building Your Own Map
- F.4 Answering an Audit / Questionnaire
- F.5 Quick Reference
Appendix G: Glossary and Further Reading
- G.1 Glossary
- G.2 The Book’s Principles, in One List
- G.3 Further Reading
- G.4 Closing Note