Agent Security
Agent security means scoping tool access tightly and requiring approval for irreversible actions, since an agent turns a decision into a real effect.
Prerequisites
Overview
An agent that can only generate text can, at worst, produce a bad answer. An agent that can call tools can take real, sometimes irreversible action — which makes excessive tool permissions the central risk agent security has to manage.
Where It Fits
Agent Decides to Act
Scoped Tool Permissions
Irreversible?
Human Approval
Tool Executes
Tool Executes
Key Points
- Least-privilege tools
- An agent should have exactly the tools its task requires, scoped as narrowly as possible — not broad access "just in case."
- Irreversibility as the risk signal
- A read-only tool call is a much smaller risk than one that sends, deletes, or modifies something permanently.
- Excessive agency
- Granting an agent more autonomy or tool access than its task actually needs is the core failure mode agent security defends against.
Interview Question
What’s the single biggest security risk specific to giving an LLM agent tool access?
Excessive agency — granting broader tool access or autonomy than the task actually needs, so a prompt injection, hallucination, or bug turns into a real, sometimes irreversible action instead of just a bad text response. The mitigation is scoping tools tightly to least privilege and requiring human approval before anything irreversible executes.
Explain It in 30 Seconds
Agent security centers on excessive agency — an agent having more tool access or autonomy than its task requires — mitigated by scoping tools to least privilege and requiring human approval before irreversible actions execute.
Real-World Stack
Technologies commonly used to implement this in production.