Agent Spoofing — KYA Glossary

Agent spoofing is impersonating a trusted agent to gain access, authority, or trust that the attacker is not entitled to — for example, pretending to be an approved shopping agent to a merchant, or posing as one agent to another.

Why it matters

If a service trusts “an agent” without verifying which agent, spoofing is the obvious attack. It can take several forms:

  • Bot/agent impersonation — claiming to be a known crawler or agent without the cryptographic proof. Signed agent traffic (e.g. Cloudflare Web Bot Auth) exists precisely to distinguish real from claimed agents.
  • Prompt injection and manipulation — OWASP lists prompt injection as the top LLM application risk; manipulating an agent’s inputs can make it act outside its mandate on behalf of the attacker.
  • Adversarial input — NIST’s adversarial-ML taxonomy catalogues evasion and related attacks against AI systems, relevant when an agent’s decisions can be steered.
  • Credential theft or replay — stealing the agent’s credentials so the attacker’s own process presents a legitimate identity. Strong authenticator binding and attestation (NIST SP 800-63; zero trust) reduce this.

Defences

  • Verify agent identity cryptographically, not by assertion.
  • Use attestation so only the approved code can assume the identity.
  • Scope credentials so a spoofed agent gains little.
  • Monitor for anomalous behaviour; log and revoke fast.

How it works in practice

The two attack families need different answers. Impersonation is defeated by cryptography: a signed HTTP message or a verifiable credential can be checked against the issuer’s key, so a claimed identity that cannot produce a valid signature is rejected. Manipulation is different — the agent is genuinely itself, but its inputs have been steered, so the defence is authority design: narrow scopes, least privilege, and human approval for high-risk actions.

Neither alone is enough. Identity controls stop a fake agent; scoping and step-up limit what a hijacked real agent can do. Keeping the two threat models separate is what makes the controls fit the risk. See Why agent identity is a new problem and the verification guide, with signing and verification code in the examples.

Related terms

Sources

  1. OWASP, Top 10 for LLM Applications (accessed 2026-10-03)
  2. NIST, AI 100-2 E2025, Adversarial Machine Learning (accessed 2026-10-03)
  3. Cloudflare, Web Bot Auth (accessed 2026-10-03)
  4. NIST, SP 800-63-4, Digital Identity Guidelines (accessed 2026-10-03)
  5. NIST NCCoE, Agentic AI Identity and Authorization Resource Hub (accessed 2026-10-03)
  6. OWASP, LLM01:2025 Prompt Injection (accessed 2026-10-03)

Know Your Agent (KYA) explains agent identity, verification and accountability. This is an explainer, not legal or compliance advice — see our Sources & methodology. New to KYA? Start with What is Know Your Agent? and the glossary.