Observable symptom: A poisoned doc in a shared index contaminates every downstream consumer. Prompt injection propagates via handoffs. Suitable correction: Treat every agent-to-agent message as a trust boundary. Partition knowledge bases by trust level. Context: The architecture-level failure the Security threat model treats end to end: every OWASP LLM and A…
Use this profile to understand the building block briefly, place it in the model, and switch to the 360° assessment when needed.
Theoretical construct: explains a term, principle, or mental model.
What organizes, connects, or makes decisions possible.
Cascading Security Failures describes a security failure in multi-agent architectures where compromised context propagates downstream through shared indexes, handoffs, or knowledge bases.
The pattern comes from security work on LLM-based multi-agent systems and summarizes failures observed in practice: a poisoned entry or manipulated handoff can compromise several downstream agents. In the source orientation, it is framed as an architectural problem that connects OWASP LLM and Agentic threats at the point where trust crosses boundaries.
Think of the system as a chain of sluice gates and check valves. Each agent receives not just content, but also its trust status. Before anything flows on, the next gate checks whether source, purpose, and permission fit together. Shared stores without separation behave like an open channel: once context is contaminated, it can spread unchecked. The architecture becomes resilient only when every handoff is checked, constrained, and logged.
Several autonomous agents share tasks, data, and decisions; that creates handoffs and dependencies where trust must be made explicit.
An agent gets only the access its role truly needs, so a mistake or compromise cannot spread through the whole system.
Handoffs are checked against fixed structures and rules before processing, instead of letting malformed or manipulated output continue downstream.
Decisions, inputs, outputs, and tool calls remain traceable so the spread path can be reconstructed later.
A supervising layer monitors behavior and can limit critical deviations, unauthorized paths, or risky transfers.
The pattern matters in RAG setups, multi-agent orchestration, tool chains, and shared knowledge bases. It helps design handoffs, storage, and permissions as security boundaries before bad behavior can scale. The trade-off is more separation, validation, and operational overhead; overly coarse partitioning can slow collaboration, reuse, and response time.
Where this building block is located in the topic model.
No structure path available.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.