<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/otto-support---the-confused-deputy-d4xmzthp7" -->

---
title: Otto Support - The Confused Deputy | daily.dev
description: Confused deputy attacks occur when an AI agent reads attacker-controlled content, such as a poisoned support ticket, email, or calendar invite, and follows...
canonical: https://daily.dev/posts/otto-support---the-confused-deputy-d4xmzthp7
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Otto Support - The Confused Deputy | daily.dev
og:description: Confused deputy attacks occur when an AI agent reads attacker-controlled content, such as a poisoned support ticket, email, or calendar invite, and follows...
og:url: https://daily.dev/posts/otto-support---the-confused-deputy-d4xmzthp7
og:image: https://api.daily.dev/og/posts/d4XmzTHp7.png
og:image:alt: Otto Support - The Confused Deputy
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Otto Support - The Confused Deputy

**[Sliver C2 Documentation](https://daily.dev/sources/bishopfox)** · 5 min read · 0 upvotes · 0 comments

## Summary

Confused deputy attacks occur when an AI agent reads attacker-controlled content, such as a poisoned support ticket, email, or calendar invite, and follows hidden instructions using its own legitimate privileges rather than the attacker's. Real-world cases including EchoLeak, ConfusedPilot, and Copilot calendar exploits illustrate this at enterprise scale. Bishop Fox's otto-support CTF reproduces the scenario via IDOR-based ticket poisoning and metadata service abuse to escalate into a support-agent role. Mitigations include separating data from instructions, per-task tool registration with least privilege, human-in-the-loop for destructive actions, and network egress controls.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://bishopfox.com/blog/otto-support-confused-deputy>

## Questions this post answers

### What is a confused deputy attack in the context of AI agents?

A confused deputy attack happens when an AI agent with tool access reads attacker-controlled content, such as a poisoned support ticket, email, or calendar invite, and executes the hidden instructions using its own legitimate privileges rather than the attacker's. The result is that the agent's actions appear authorized and show up under the user's own identity in audit logs, even though an attacker triggered them.

_Teams securing agentic AI workflows can follow emerging confused-deputy research and mitigations on daily.dev._

### What mitigations reduce the risk of confused deputy attacks in AI agent systems?

Layered defenses work best: separating data from instructions using prompting and markup, restricting agents to per-task tool registrations instead of granting all tools to one agent, enforcing least privilege so read-only tools lack destructive write capability without human approval, and adding network egress controls that only permit approved destinations so exfiltrated data cannot leave the environment.

_Engineers designing agent permission models can track practical mitigation patterns like these on daily.dev._

### What real-world incidents demonstrate confused deputy attacks against Microsoft Copilot?

EchoLeak (disclosed around June 2025) let a crafted email trick Microsoft 365 Copilot into using its own enterprise access to retrieve and exfiltrate confidential data without direct attacker access to underlying resources. A separate incident named ConfusedPilot (August 2024) had an agent monitoring a distribution list leak confidential data back to an attacker via email after processing a malicious prompt.

_Developers evaluating Copilot-style agent risk can follow incident writeups like these on daily.dev._

## Similar posts on daily.dev

- [AI agents are a confused deputy with the keys to your kingdom](https://daily.dev/posts/ai-agents-are-a-confused-deputy-with-the-keys-to-your-kingdom-hdyex7svh) · Stack Overflow Blog · 0 upvotes · 0 comments
- [Agentic AI Security: Defending Against Prompt Injection and Tool Misuse](https://daily.dev/posts/agentic-ai-security-defending-against-prompt-injection-and-tool-misuse-8x1r1ytqn) · Machine Learning Mastery · 1 upvotes · 0 comments
- [AI agents can bypass guardrails and put credentials at risk, Okta study finds](https://daily.dev/posts/ai-agents-can-bypass-guardrails-and-put-credentials-at-risk-okta-study-finds-cwzxq24mf) · CSO Online · 2 upvotes · 0 comments

---

Tags: [#ai-agents](https://daily.dev/tags/ai-agents), [#mcp](https://daily.dev/tags/mcp), [#prompt-injection](https://daily.dev/tags/prompt-injection), [#microsoft-copilot](https://daily.dev/tags/microsoft-copilot)

[View this post on daily.dev](https://daily.dev/posts/otto-support---the-confused-deputy-d4xmzthp7)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Otto Support - The Confused Deputy","url":"https://daily.dev/posts/otto-support---the-confused-deputy-d4xmzthp7","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/otto-support---the-confused-deputy-d4xmzthp7"},"datePublished":"2026-08-23T12:22:41.513Z","dateModified":"2026-08-23T12:49:42.654Z","description":"Confused deputy attacks occur when an AI agent reads attacker-controlled content, such as a poisoned support ticket, email, or calendar invite, and follows...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/b9136cc8981430a87bdb4c899d0223df?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/b9136cc8981430a87bdb4c899d0223df?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Sliver C2 Documentation","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Sliver C2 Documentation","logo":"https://media.daily.dev/image/upload/logos/placeholder.jpg","url":"https://daily.dev/sources/bishopfox"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/otto-support---the-confused-deputy-d4xmzthp7","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"ai-agents,mcp,prompt-injection,microsoft-copilot","timeRequired":"PT5M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Sliver C2 Documentation","item":"https://daily.dev/sources/bishopfox"},{"@type":"ListItem","position":3,"name":"Otto Support - The Confused Deputy"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/otto-support---the-confused-deputy-d4xmzthp7#faq","mainEntity":[{"@type":"Question","name":"What is a confused deputy attack in the context of AI agents?","acceptedAnswer":{"@type":"Answer","text":"A confused deputy attack happens when an AI agent with tool access reads attacker-controlled content, such as a poisoned support ticket, email, or calendar invite, and executes the hidden instructions using its own legitimate privileges rather than the attacker's. The result is that the agent's actions appear authorized and show up under the user's own identity in audit logs, even though an attacker triggered them. Teams securing agentic AI workflows can follow emerging confused-deputy research and mitigations on daily.dev."}},{"@type":"Question","name":"What mitigations reduce the risk of confused deputy attacks in AI agent systems?","acceptedAnswer":{"@type":"Answer","text":"Layered defenses work best: separating data from instructions using prompting and markup, restricting agents to per-task tool registrations instead of granting all tools to one agent, enforcing least privilege so read-only tools lack destructive write capability without human approval, and adding network egress controls that only permit approved destinations so exfiltrated data cannot leave the environment. Engineers designing agent permission models can track practical mitigation patterns like these on daily.dev."}},{"@type":"Question","name":"What real-world incidents demonstrate confused deputy attacks against Microsoft Copilot?","acceptedAnswer":{"@type":"Answer","text":"EchoLeak (disclosed around June 2025) let a crafted email trick Microsoft 365 Copilot into using its own enterprise access to retrieve and exfiltrate confidential data without direct attacker access to underlying resources. A separate incident named ConfusedPilot (August 2024) had an agent monitoring a distribution list leak confidential data back to an attacker via email after processing a malicious prompt. Developers evaluating Copilot-style agent risk can follow incident writeups like these on daily.dev."}}]}
```

