Cross-post. Original: stellarbytecapital.com/blog/ai-agent-security-threat-model

While a chatbot only produces text, an autonomous agent takes actions: it calls tools, runs code, moves data, and spends money. That shift changes the security problem entirely. "Is the prompt safe?" is no longer the question. The question is: what can this agent do, and what stops it when it goes wrong?

Treating agent security as prompt filtering is how teams end up with an impressive demo and a production incident. You need a threat model. Here's ours.

Three planes of attack surface

An agent's exposure lives on three distinct planes. Confusing them is why defenses miss: