Zero Trust Agency: Mitigating the Confused Deputy in Autonomous AI Systems
Rajkumar Vaghashiya, Anshul · Team AgentZero
Submitted to Defensive Acceleration Hackathon. Sprint projects are early-stage work by participants, not Apart Research publications.
This project addresses the critical "Confused Deputy" vulnerability in Agentic AI, where agents operating with static "God-mode" permissions are hijacked via prompt injection to attack enterprise systems. We developed a Zero Trust Architecture that replaces these static credentials with Identity Propagation via RFC 8693 (Token Exchange). This compels agents to cryptographically "borrow" the human user's identity ("On-Behalf-Of") for every interaction, ensuring they can only access resources explicitly authorized for that user. Our MVP simulation demonstrated that this architecture deterministically blocks 100% of privilege escalation and lateral movement attempts by enforcing hard permission boundaries at the infrastructure layer, rendering prompt injection attacks ineffective against unauthorized tools.
Reviews
No public critique yet.
Cite this project
@misc{vaghashiya2025zero,
title = {{Zero Trust Agency: Mitigating the Confused Deputy in Autonomous AI Systems}},
author = {Rajkumar Vaghashiya and Anshul},
year = {2025},
month = nov,
note = {Submitted to Defensive Acceleration Hackathon, an Apart Research Sprint},
howpublished = {\url{https://apartresearch.com/sprints/projects/zero-trust-agency-mitigating-the-confused-deputy-in-autonomous-ai-systems-uea3}},
url = {https://apartresearch.com/sprints/projects/zero-trust-agency-mitigating-the-confused-deputy-in-autonomous-ai-systems-uea3}
}More from Defensive Acceleration Hackathon
- View project: Neops - DevSecOps for the AI era
Neops - DevSecOps for the AI era
Broad Bros
NEOps is a CLI-based tool that embeds AI safety into your product lifecycle from day one. While development teams routinely build cybersecurity checks, AI-safety often comes later—or not at all. NEOps fills that gap by …
- View project: Assisted Audit of Solana Programs
Assisted Audit of Solana Programs
GLAM
Multi-agent solution that assists in auditing Solana programs, allows to consolidate audit findings into a knowledge base, and can integrate into CI/CD pipelines to prevent security regressions.
- View project: Mechanistic Watchdog
Mechanistic Watchdog
SL5
Mechanistic Watchdog is a mechanistic-interpretability-based “cognitive kill switch” for language models. Instead of only filtering final text, we monitor a model’s internal activations in real time and learn linear …