Adversaries exploit inter-agent delegation, trust relationships, and workflow dependencies — rather than attacking a single agent directly — to escalate privilege or manipulate AI-driven operations across the system. In a multi-agent system: An attacker repeatedly re-routes a request between two interdependent agents so each treats the other's prior handling…
Use this profile to understand the building block briefly, place it in the model, and switch to the 360° assessment when needed.
Theoretical construct: explains a term, principle, or mental model.
What organizes, connects, or makes decisions possible.
Human attacks on multi-agent systems are deliberate interventions that manipulate or abuse agents, their communication, or their tools.
The topic grew from security analysis of agentic systems as greater autonomy and coupling exposed new attack surfaces. OWASP describes it as a threat category for agentic AI; it has no single originator.
An attacker may craft inputs, steal credentials, induce risky handoffs, or misuse tools. In a multi-agent system, a compromised agent can propagate false or harmful instructions. Trust boundaries, least privilege, approval for consequential actions, and logging can break the chain.
People alter input or context to influence an agent's decisions and handoffs.
A compromised agent can spread false or harmful instructions to other agents.
Permissions, approvals, and isolation limit the consequences of an attack.
The category is central to the design, operation, and governance of agentic systems. Controls must cover the whole agent network, tools, identities, and human operating errors.
Where this building block is located in the topic model.
No structure path available.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.