<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/confused-deputy-the-old-bug-that-ai-agents-keep-reintroducing-ihacvvde5" -->

---
title: Confused Deputy: The Old Bug That AI Agents Keep...
description: The Confused Deputy problem, first documented in 1988 when a compiler with elevated permissions overwrote a billing file, is resurfacing at scale through AI...
canonical: https://daily.dev/posts/confused-deputy-the-old-bug-that-ai-agents-keep-reintroducing-ihacvvde5
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Confused Deputy: The Old Bug That AI Agents Keep Reintroducing | daily.dev
og:description: The Confused Deputy problem, first documented in 1988 when a compiler with elevated permissions overwrote a billing file, is resurfacing at scale through AI...
og:url: https://daily.dev/posts/confused-deputy-the-old-bug-that-ai-agents-keep-reintroducing-ihacvvde5
og:image: https://api.daily.dev/og/posts/IHAcVVDe5.png
og:image:alt: Confused Deputy: The Old Bug That AI Agents Keep Reintroducing
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Confused Deputy: The Old Bug That AI Agents Keep Reintroducing

**[Auth0](https://daily.dev/sources/auth0)** · 11 min read · 1 upvotes · 0 comments

## Summary

The Confused Deputy problem, first documented in 1988 when a compiler with elevated permissions overwrote a billing file, is resurfacing at scale through AI agents. Agents hold broad standing permissions and process instructions, data, and untrusted content through the same undifferentiated natural-language channel, making them easy to trick into misusing their authority. A February 2026 real-world incident (dubbed 'Clinejection') shows the pattern end to end: a GitHub issue-triage bot with shell access was manipulated via a crafted issue title, leading to a poisoned GitHub Actions cache, a compromised npm publishing token, and a tampered package downloaded roughly 4,000 times before detection. The piece argues that known fixes still apply: least privilege, capability-based security, explicit permission transfer, task-scoped short-lived credentials, capability-scoped permissions, keeping credentials out of model reach, and human-in-the-loop approval for high-risk actions. Auth0 positions its Token Vault and agent-identity products around these principles.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://auth0.com/blog/confused-deputy-the-old-bug-that-ai-agents-keep-reintroducing>

## Questions this post answers

### What is the Confused Deputy problem and how does it relate to AI agent security?

The Confused Deputy problem occurs when a program with legitimate authority is tricked by a less-privileged actor into misusing that authority on the actor's behalf. First documented in 1988 when a compiler overwrote a billing file using its own write permissions, it reappears with AI agents because agents hold broad standing permissions and process instructions, data, and untrusted content through the same natural-language channel with no way to distinguish trusted commands from injected content.

_Engineers designing agent permission models track emerging confused-deputy exploits and mitigations on daily.dev._

### How did the Clinejection attack compromise an npm package through a GitHub issue-triage bot?

An authenticated GitHub issue-triage bot with shell execution rights processed an issue whose crafted title contained an embedded instruction, causing the agent to execute an attacker-supplied command. The attacker then flooded the shared GitHub Actions cache with junk data to poison cache entries used by a separate, more privileged nightly release workflow, eventually gaining access to the project's npm publishing token and publishing a tampered package with a malicious install script, downloaded roughly 4,000 times over about eight hours before being caught.

_Teams securing CI/CD pipelines against agent-driven supply chain attacks follow incidents like this on daily.dev._

### What are the recommended fixes to prevent AI agents from being exploited via confused deputy attacks?

Recommended fixes include task-scoped, short-lived credentials instead of standing OAuth scopes; capability-scoped permissions narrowed to specific business actions rather than broad verbs like billing:write; keeping credentials in a separate deterministic execution layer the model never directly accesses; and human-in-the-loop approval for expensive, irreversible, or high-risk actions, replacing blanket session-level approval with per-action confirmation.

_Developers hardening agent permission systems compare these authorization patterns on daily.dev._

## Similar posts on daily.dev

- [A GitHub Issue Title Compromised 4,000 Developer Machines](https://daily.dev/posts/a-github-issue-title-compromised-4-000-developer-machines-e5lzhfwln) · Hacker News · 1 upvotes · 0 comments
- [AI agents are a confused deputy with the keys to your kingdom](https://daily.dev/posts/ai-agents-are-a-confused-deputy-with-the-keys-to-your-kingdom-hdyex7svh) · Stack Overflow Blog · 0 upvotes · 0 comments
- [How “Clinejection” Turned an AI Bot into a Supply Chain Attack](https://daily.dev/posts/how-clinejection-turned-an-ai-bot-into-a-supply-chain-attack-jkyi3izxq) · Snyk · 1 upvotes · 0 comments

---

Tags: [#cyber](https://daily.dev/tags/cyber), [#ai-agents](https://daily.dev/tags/ai-agents), [#oauth](https://daily.dev/tags/oauth), [#prompt-injection](https://daily.dev/tags/prompt-injection)

[View this post on daily.dev](https://daily.dev/posts/confused-deputy-the-old-bug-that-ai-agents-keep-reintroducing-ihacvvde5)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Confused Deputy: The Old Bug That AI Agents Keep Reintroducing","url":"https://daily.dev/posts/confused-deputy-the-old-bug-that-ai-agents-keep-reintroducing-ihacvvde5","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/confused-deputy-the-old-bug-that-ai-agents-keep-reintroducing-ihacvvde5"},"datePublished":"2026-09-22T16:01:08.441Z","dateModified":"2026-09-22T16:02:21.803Z","description":"The Confused Deputy problem, first documented in 1988 when a compiler with elevated permissions overwrote a billing file, is resurfacing at scale through AI...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/1fc6e65ac8dd0f07706b18a449d3bfb8?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/1fc6e65ac8dd0f07706b18a449d3bfb8?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Auth0","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Auth0","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/6510ffa7350449618fbacdddae663b82","url":"https://daily.dev/sources/auth0"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/confused-deputy-the-old-bug-that-ai-agents-keep-reintroducing-ihacvvde5","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"cyber,ai-agents,oauth,prompt-injection","timeRequired":"PT11M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Auth0","item":"https://daily.dev/sources/auth0"},{"@type":"ListItem","position":3,"name":"Confused Deputy: The Old Bug That AI Agents Keep Reintroducing"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/confused-deputy-the-old-bug-that-ai-agents-keep-reintroducing-ihacvvde5#faq","mainEntity":[{"@type":"Question","name":"What is the Confused Deputy problem and how does it relate to AI agent security?","acceptedAnswer":{"@type":"Answer","text":"The Confused Deputy problem occurs when a program with legitimate authority is tricked by a less-privileged actor into misusing that authority on the actor's behalf. First documented in 1988 when a compiler overwrote a billing file using its own write permissions, it reappears with AI agents because agents hold broad standing permissions and process instructions, data, and untrusted content through the same natural-language channel with no way to distinguish trusted commands from injected content. Engineers designing agent permission models track emerging confused-deputy exploits and mitigations on daily.dev."}},{"@type":"Question","name":"How did the Clinejection attack compromise an npm package through a GitHub issue-triage bot?","acceptedAnswer":{"@type":"Answer","text":"An authenticated GitHub issue-triage bot with shell execution rights processed an issue whose crafted title contained an embedded instruction, causing the agent to execute an attacker-supplied command. The attacker then flooded the shared GitHub Actions cache with junk data to poison cache entries used by a separate, more privileged nightly release workflow, eventually gaining access to the project's npm publishing token and publishing a tampered package with a malicious install script, downloaded roughly 4,000 times over about eight hours before being caught. Teams securing CI/CD pipelines against agent-driven supply chain attacks follow incidents like this on daily.dev."}},{"@type":"Question","name":"What are the recommended fixes to prevent AI agents from being exploited via confused deputy attacks?","acceptedAnswer":{"@type":"Answer","text":"Recommended fixes include task-scoped, short-lived credentials instead of standing OAuth scopes; capability-scoped permissions narrowed to specific business actions rather than broad verbs like billing:write; keeping credentials in a separate deterministic execution layer the model never directly accesses; and human-in-the-loop approval for expensive, irreversible, or high-risk actions, replacing blanket session-level approval with per-action confirmation. Developers hardening agent permission systems compare these authorization patterns on daily.dev."}}]}
```

