Learn
One definition per page: what each term means, how it works and how to detect it.
- A2A session smuggling
A2A session smuggling is an attack in which one agent injects extra turns or instructions into a running agent-to-agent session, and the receiving agent acts on them.
- Agent boundary protection
Agent boundary protection means inspecting the traffic that crosses the line between an AI agent and the tools or agents it uses: the list of tools, each call and each response. It catches attacks that arrive as instructions rather than malformed requests.
- BFLA
Broken function level authorisation, or BFLA, is when an API lets a caller use a function they should not have, such as an ordinary user calling an administrative endpoint. BOLA is about the wrong data; BFLA is about the wrong action.
- BOLA
Broken object level authorisation, or BOLA, is when an API returns or changes an object without checking that the caller is allowed to touch it. An attacker changes an identifier in the request and reads someone else's data. It is the first risk in the OWASP API Security Top 10.
- Credential stuffing
Credential stuffing is the automated use of usernames and passwords leaked from one service to log in to another. It works because people reuse passwords, and it looks like many ordinary failed logins spread across many accounts.
- MCP gateway
An MCP gateway is a service that sits between AI agents and MCP tool servers. Agents call the gateway, and it forwards each exchange to the right server. A security gateway also inspects what passes and can refuse it.
- MCP rug-pull
An MCP rug-pull is a change made to a tool after it has been approved. The name stays the same while the description, schema or behaviour changes, so the agent calls something nobody reviewed. It is detected by recording each tool definition on first use and comparing every later version against it.
- Secrets in tool arguments
Secrets in tool arguments are credentials an AI agent passes to a tool as ordinary parameters: a cloud key, a token, a private key. The call is authorised and well formed, and the secret now sits with whoever runs the tool server.
- Tool poisoning
Tool poisoning is an attack in which instructions for an AI agent are hidden inside a tool's description. The agent reads the description to learn how to use the tool, obeys the hidden instruction, and then makes calls that every other control sees as authorised.