futureofagents.org
RESEARCH DOSSIER / 2026.10INITIAL EDITION · OPEN FOR REVIEW
← Back to research index

Minimize what an agent can touch

Security & Containment.

Security controls must exist outside the model’s own promises.

EVIDENCE STATUS / LAUNCH

This is a scoped research dossier, not a completed systematic review or an independently tested result. It identifies methods, questions and source trails for future reporting.

01

Least privilege

Prefer read-only accounts and task-specific tools. Production writes, secrets access and destructive operations should require specific authorization.

02

Prompt injection is a boundary problem

Untrusted content may try to redirect behavior through retrieved pages, files, logs or peers. No prompt alone can reliably isolate every external side effect.

03

Independent evidence

Keep immutable or access-separated logs outside the agent’s credentials. A compromised execution environment must not be able to erase every record.

SUGGESTED VERIFICATION METHOD

What would count as evidence?

Record threat model, attacker access, denial logs, isolation limits and tested mitigations.

STARTING SOURCE TRAIL

Documents to examine

  • OWASP — Excessive Agency
  • MCP 2026 Tools Specification

These are starting points, not claims that every document has been independently reproduced.

Read our cited field note →
EDITORIAL / VERSION RECORD

Edition 1.0 · 09 October 2026

Initial research brief published. No earlier revisions or submitted public corrections are claimed.

Suggest a documented correction ↗