AI Agent Authentication and Authorization (IETF Internet-Draft)

(datatracker.ietf.org)

3 points | by jhgaylor 5 hours ago ago

2 comments

  • jhgaylor 5 hours ago ago

    This is at the bottom of section 8

    > The Large Language Model MUST NOT have access to an agent's credentials or to credentials that may be needed to access tools and services. This prevents the Large Language Model from using, exposing, or being manipulated via prompt injection into disclosing the credentials.

    I knew this but I just went ahead doing it wrong anyway. As a stop gap I gave all my secrets handles so the LLM and I could discuss them but I am just pretending that my agent is trustworthy. We have some big names here so hopefully there is better tooling in our future.