← Scenario library

The Link That Hired an Insider

One click provisions an attacker-configured agent inside your own workspace

Technique first revealed 23 Jul 2026

Tool-Using Agent
UntrustedAgent coreOversightThe real worldgoalβ§šβ§šβ§šβ§šπŸ§‘UserπŸŽ›οΈOrchestrator /Agent Loop🧠LLMπŸ”Identity &PermissionsπŸ”§Tool Runtimeβœ‹Human ApprovalGateπŸ”ŒExternal APIsπŸ—„οΈBusinessDatabase🌐UntrustedContentπŸ“Audit Logging🌐Malicious link
InstructionsDataActionsControl / decisionFeedback / logs⧚crosses a trust boundary
πŸ‘† Click a component or flow to inspect
SetupStep 1 / 6

An authenticated workspace

You are signed in to an agent-building platform. Your session is trusted: the platform already knows it is you, and it will do things on your behalf without asking you to log in again for every action.

AI RiskAtlas is an educational model of how GenAI & agentic systems work and fail. Architectures and payloads are illustrative and simplified for learning β€” not operational guidance. Real-world cases are summarised from public reporting.

Sources & further reading β†’Β·Built by Shi Yuan β†—