logo

Agentic AI Tooling: Why Runtime Security Is the Missing Layer

ID: 5e803f7a-6fa0-5f2c-8476-e3b2e46f9b2c

STIX ID: report--5e803f7a-6fa0-5f2c-8476-e3b2e46f9b2c

Feed Name: Sysdig Blog

Threat Score
70/100

Date Published: 2026-05-19

Date Updated: 2026-05-19

...
...

This report analyzes emerging attack surfaces in AI agent stacks (MCPs, skills, SDKs, managed platforms, orchestration) and documents real-world techniques — MCP tool poisoning, prompt-injection via tool responses, and coding-agent credential theft — citing specific disclosures (CVE-2025-32711 and a July 2025 Supabase+Cursor demonstration). It maps techniques to MITRE ATLAS (AML.T0080–T0086), demonstrates detection examples (Falco rules), and prescribes layered mitigations: syscall-level runtime instrumentation, strict capability scoping, MCP auditing, and tool-call-level auditing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.