Open cardosec

Case C1AB63 · AI security · L2 Practitioner

Excessive Agency

Practise as: Explain it · Interview

Interview questionAn LLM agent is being given access to company tools. What is excessive agency and how do you limit it?

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. OWASP LLM06: damaging actions from excessive functionality, excessive permissions, or excessive autonomy.
  2. Functionality: expose narrow tools (read_ticket) not generic ones (run_shell, send_any_email).
  3. Permissions: tools run with the end user's scoped OAuth token, not a shared service account with admin rights.
  4. Autonomy: require human confirmation for irreversible or high-impact actions like payments, deletes, external sends.
  5. Enforce authorization in the downstream API, never by asking the model to decide if an action is allowed.

If the interviewer pushes back

  • How do you design human-in-the-loop approval so users do not rubber-stamp every prompt?

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.