{
  "slug": "ai-agent",
  "name": "Agents, MCP, and retrieval",
  "category": "Identity",
  "summary": "Keep retrieved content, model output, tool authority, and user consent separate throughout an AI-assisted workflow.",
  "scope": "Defensive study and review of artifacts supplied by their owner. Record missing evidence as an open question.",
  "inputs": [
    "Tool definitions and granted scopes",
    "Retrieval permissions and provenance metadata",
    "Human approval and audit requirements"
  ],
  "review": [
    {
      "title": "Model authority separately",
      "body": "Document what the model may suggest, what a tool may do, and which identity authorizes the tool invocation."
    },
    {
      "title": "Review retrieval boundaries",
      "body": "Require authorization and provenance checks before tenant or sensitive documents reach context."
    },
    {
      "title": "Validate before action",
      "body": "Make tools independently validate typed arguments, resource scope, and policy rather than trusting generated instructions."
    },
    {
      "title": "Make consent progressive",
      "body": "Present meaningful scope at approval time and retain an audit trail for sensitive operations."
    }
  ],
  "outputs": [
    "Authority and consent map",
    "Retrieval boundary policy",
    "Tool validation contract"
  ],
  "pitfalls": [
    "Granting a broad token to a narrow task",
    "Treating retrieved text as instructions",
    "Equating a model error with an authorized security impact"
  ],
  "references": {
    "resources": [
      {
        "id": "mcp-progressive-scope-authority",
        "title": "MCP scope selection: progressive consent and accumulated authority",
        "url": "https://vulns.co/research/resources/mcp-progressive-scope-authority/"
      },
      {
        "id": "owasp-rag-retrieval-permission-boundaries",
        "title": "OWASP LLM08:2025: retrieval permissions and knowledge provenance",
        "url": "https://vulns.co/research/resources/owasp-rag-retrieval-permission-boundaries/"
      },
      {
        "id": "owasp-llm-output-consumer-trust",
        "title": "OWASP LLM05:2025: generated-output consumer trust",
        "url": "https://vulns.co/research/resources/owasp-llm-output-consumer-trust/"
      }
    ],
    "diagrams": [
      {
        "id": "ai-content-authority-separation",
        "title": "Retrieved content is data, not authority",
        "url": "https://vulns.co/research/diagrams/ai-content-authority-separation/"
      }
    ],
    "reports": [
      {
        "id": "google-gemini-enterprise-connected-content-memory-integrity-2026",
        "title": "Gemini Enterprise connected-content trust failure allowed persistent-memory modification",
        "url": "https://vulns.co/research/reports/google-gemini-enterprise-connected-content-memory-integrity-2026/"
      },
      {
        "id": "google-gemini-colab-rendering-boundary-2025",
        "title": "Gemini-to-Colab rendering boundary exposed Workspace data",
        "url": "https://vulns.co/research/reports/google-gemini-colab-rendering-boundary-2025/"
      }
    ]
  },
  "provenance": {
    "publisher": "vulns.co / GK Data",
    "guide_updated": "2026-10-11",
    "library_as_of": "2026-10-04",
    "library_commit": "d5550c7891119cf1379e235721541c947850a3b3"
  },
  "url": "https://vulns.co/skills/ai-agent/",
  "markdown_url": "https://vulns.co/skills/ai-agent/SKILL.md"
}
