Reference library

Topics in agentic AI security

Plain, source-cited reference pages on the threats, terms, and incidents that define agentic AI security. Each page is written answer-first, cites primary sources, and links to the underlying research. This library is being built out; the pages below are live.

Published

Pillar guide

Agentic AI Security

Securing autonomous AI agents: why it is a distinct discipline, the main threats, the three-layer defense model, least agency, and the standards. The hub the rest of this cluster links back to.

MCP

MCP Security

The Model Context Protocol attack surface: tool poisoning, rug pulls, cross-server shadowing, and why the connect-time-vs-runtime gap is the root issue.

Prompt injection

Indirect Prompt Injection

Hidden instructions in the content an agent reads — the mechanism behind EchoLeak — and why identity controls alone cannot stop it.

MCP Security

Tool Poisoning

Malicious instructions hidden in a tool's description that steer an agent into acting for an attacker.

In progress

The following reference pages are being written to the same standard and will be published into this section. Until each ships, the research papers and the glossary cover the same ground.

How this section is built. Every topic page follows one template: an exact-term H1, a bottom-line-up-front answer, an extractable “key facts” list, question-headed sections answered answer-first, inline primary-source citations, a brief factual note on how Crawdad addresses the issue, and cross-links to related pages and the relevant white paper. Each carries TechArticle, FAQPage, and DefinedTerm structured data. See Tool Poisoning for the pattern.

Related

Research

White papers

The threat landscape, a runtime reference architecture, and a field briefing.

Reference

Glossary

Short definitions for every term in the space.

Open data

Benchmark corpus ↗

Contemporary agent attacks you can clone and run yourself (CC BY 4.0).