A malicious or compromised agent operates outside its intended boundaries inside a multi-agent architecture, exploiting inter-agent trust to manipulate decisions, corrupt data, or execute unauthorized actions undetected. In a multi-agent system: A compromised specialist agent impersonates a financial-approval role and injects a fraudulent transaction that do…
Use this profile to understand the building block briefly, place it in the model, and switch to the 360° assessment when needed.
Theoretical construct: explains a term, principle, or mental model.
What organizes, connects, or makes decisions possible.
A rogue agent is a malicious or compromised agent that leaves its intended boundaries in an agentic system and thereby threatens decisions, data, or actions.
The term emerged from security analysis of agentic and multi-agent systems. OWASP treats rogue agents as a threat because an agent with legitimate capabilities but manipulated behaviour can exploit trust and delegation within the system.
Imagine specialised agents handing tasks and results to one another. If one is compromised, it may forge instructions, corrupt data, or invoke unauthorised tools. Trust assumptions between agents are therefore insufficient: identity, permissions, and consequential hand-offs need enforceable checks. Least privilege, independent validation, logging, and shutdown controls reduce the blast radius.
A compromised agent abuses legitimate capabilities or trust to act outside its mandate.
Agent-to-agent messages and results must be checked and authorised like external input.
Least privilege, independent controls, audit trails, and stop points limit impact and support investigation.
Rogue agents matter when agents plan, delegate, or use tools autonomously. Security depends on enforceable boundaries and accountability; a supervisor alone does not prove correct or uncompromised behaviour.
Where this building block is located in the topic model.
No structure path available.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.