Agent Spoofing — KYA Glossary

Agent spoofing is impersonating a trusted agent to gain access, authority, or trust that the attacker is not entitled to — for example, pretending to be an approved shopping agent to a merchant, or posing as one agent to another.

Why it matters

If a service trusts “an agent” without verifying which agent, spoofing is the obvious attack. It can take several forms:

  • Bot/agent impersonation — claiming to be a known crawler or agent without the cryptographic proof. Signed agent traffic (e.g. Cloudflare Web Bot Auth) exists precisely to distinguish real from claimed agents.
  • Prompt injection and manipulation — OWASP lists prompt injection as the top LLM application risk; manipulating an agent’s inputs can make it act outside its mandate on behalf of the attacker.
  • Adversarial input — NIST’s adversarial-ML taxonomy catalogues evasion and related attacks against AI systems, relevant when an agent’s decisions can be steered.
  • Credential theft or replay — stealing the agent’s credentials so the attacker’s own process presents a legitimate identity. Strong authenticator binding and attestation (NIST SP 800-63; zero trust) reduce this.

Defences

  • Verify agent identity cryptographically, not by assertion.
  • Use attestation so only the approved code can assume the identity.
  • Scope credentials so a spoofed agent gains little.
  • Monitor for anomalous behaviour; log and revoke fast.

Related

Sources

  1. OWASP, Top 10 for LLM Applications — https://genai.owasp.org/llm-top-10/ (accessed 2026-10-03)
  2. NIST, AI 100-2 E2025, Adversarial Machine Learning — https://csrc.nist.gov/pubs/ai/100/2/e2025/final (accessed 2026-10-03)
  3. Cloudflare, Web Bot Auth — https://developers.cloudflare.com/bots/reference/bot-verification/web-bot-auth/ (accessed 2026-10-03)
  4. NIST, SP 800-63-4 — https://pages.nist.gov/800-63-4/ (accessed 2026-10-03)