Agent spoofing is impersonating a trusted agent to gain access, authority, or trust that the attacker is not entitled to — for example, pretending to be an approved shopping agent to a merchant, or posing as one agent to another.
Why it matters
If a service trusts “an agent” without verifying which agent, spoofing is the obvious attack. It can take several forms:
- Bot/agent impersonation — claiming to be a known crawler or agent without the cryptographic proof. Signed agent traffic (e.g. Cloudflare Web Bot Auth) exists precisely to distinguish real from claimed agents.
- Prompt injection and manipulation — OWASP lists prompt injection as the top LLM application risk; manipulating an agent’s inputs can make it act outside its mandate on behalf of the attacker.
- Adversarial input — NIST’s adversarial-ML taxonomy catalogues evasion and related attacks against AI systems, relevant when an agent’s decisions can be steered.
- Credential theft or replay — stealing the agent’s credentials so the attacker’s own process presents a legitimate identity. Strong authenticator binding and attestation (NIST SP 800-63; zero trust) reduce this.
Defences
- Verify agent identity cryptographically, not by assertion.
- Use attestation so only the approved code can assume the identity.
- Scope credentials so a spoofed agent gains little.
- Monitor for anomalous behaviour; log and revoke fast.
Related
Sources
- OWASP, Top 10 for LLM Applications — https://genai.owasp.org/llm-top-10/ (accessed 2026-10-03)
- NIST, AI 100-2 E2025, Adversarial Machine Learning — https://csrc.nist.gov/pubs/ai/100/2/e2025/final (accessed 2026-10-03)
- Cloudflare, Web Bot Auth — https://developers.cloudflare.com/bots/reference/bot-verification/web-bot-auth/ (accessed 2026-10-03)
- NIST, SP 800-63-4 — https://pages.nist.gov/800-63-4/ (accessed 2026-10-03)