Agent spoofing is impersonating a trusted agent to gain access, authority, or trust that the attacker is not entitled to — for example, pretending to be an approved shopping agent to a merchant, or posing as one agent to another.
Why it matters
If a service trusts “an agent” without verifying which agent, spoofing is the obvious attack. It can take several forms:
- Bot/agent impersonation — claiming to be a known crawler or agent without the cryptographic proof. Signed agent traffic (e.g. Cloudflare Web Bot Auth) exists precisely to distinguish real from claimed agents.
- Prompt injection and manipulation — OWASP lists prompt injection as the top LLM application risk; manipulating an agent’s inputs can make it act outside its mandate on behalf of the attacker.
- Adversarial input — NIST’s adversarial-ML taxonomy catalogues evasion and related attacks against AI systems, relevant when an agent’s decisions can be steered.
- Credential theft or replay — stealing the agent’s credentials so the attacker’s own process presents a legitimate identity. Strong authenticator binding and attestation (NIST SP 800-63; zero trust) reduce this.
Defences
- Verify agent identity cryptographically, not by assertion.
- Use attestation so only the approved code can assume the identity.
- Scope credentials so a spoofed agent gains little.
- Monitor for anomalous behaviour; log and revoke fast.
How it works in practice
The two attack families need different answers. Impersonation is defeated by cryptography: a signed HTTP message or a verifiable credential can be checked against the issuer’s key, so a claimed identity that cannot produce a valid signature is rejected. Manipulation is different — the agent is genuinely itself, but its inputs have been steered, so the defence is authority design: narrow scopes, least privilege, and human approval for high-risk actions.
Neither alone is enough. Identity controls stop a fake agent; scoping and step-up limit what a hijacked real agent can do. Keeping the two threat models separate is what makes the controls fit the risk. See Why agent identity is a new problem and the verification guide, with signing and verification code in the examples.
Related terms
Sources
- OWASP, Top 10 for LLM Applications (accessed 2026-10-03)
- NIST, AI 100-2 E2025, Adversarial Machine Learning (accessed 2026-10-03)
- Cloudflare, Web Bot Auth (accessed 2026-10-03)
- NIST, SP 800-63-4, Digital Identity Guidelines (accessed 2026-10-03)
- NIST NCCoE, Agentic AI Identity and Authorization Resource Hub (accessed 2026-10-03)
- OWASP, LLM01:2025 Prompt Injection (accessed 2026-10-03)
Know Your Agent (KYA) explains agent identity, verification and accountability. This is an explainer, not legal or compliance advice — see our Sources & methodology. New to KYA? Start with What is Know Your Agent? and the glossary.