cd /news/ai-agents/your-agent-is-only-as-safe-as-the-to… · home › topics › ai-agents › article
[ARTICLE · art-142916] src=dev.to ↗ pub= topic=ai-agents verified=true sentiment=↓ negative

Your Agent Is Only as Safe as the Token It Borrowed

A security researcher disclosed that an estimated 17.3 trillion stored rows across Microsoft datasets were reachable through a single internal analytics service because the service never verified the signature on a login token, allowing him to assume an administrator's identity. The same week, a well-known terminal project reversed its public position and shipped MCP support, while Hacker News discussions highlighted always-on agents, widening agent permissions, and a product that ignores user permissions. The write-up argues agent safety failures stem from unverified identity, over-scoped authority, and permanent credentials rather than from the models themselves.

by read2 min views1 publishedOct 1, 2026

A security researcher published a write-up this week describing how an estimated 17.3 trillion stored rows across Microsoft datasets were reachable through a single internal analytics service. The root cause wasn't a sophisticated exploit. The service never checked the signature on a login token. That one missing check let him claim an administrator's identity and run queries he had no business running.

Same week, on the other end of the stack, a well-known terminal project reversed its long public position and shipped MCP support — essentially conceding that agent tool interfaces are so hard to compose cleanly that the "right" design keeps moving. And the recurring theme on Hacker News came from three directions at once: always-on agents that keep working while you sleep, conversational agents that quietly widen what they can see, and a widely-shared product that "blatantly ignores user permissions."

None of these are stories about a model going rogue. They're stories about identity that nobody verified.

When you give an agent a capability, you're not just giving it a prompt. You're giving it an identity: a token, a key, a service account, a session. And that identity usually comes with more scope, longer life, and thinner auditing than anything a human would get.

Three failure modes show up again and again:

Unverified identity. Someone downstream trusts a token without checking who it really is — the 17-trillion-row story in one sentence. An agent wiring services together inherits every one of those assumptions.

Over-scoped authority. Your support bot needs to read tickets. It ships with write access to everything, because scoping is tedious. Now one bad tool call can rewrite data instead of reading it.

Permanent credentials. Tokens that never expire, keys pasted into env files, service accounts created "temporarily" two years ago. The longer a credential lives, the more chances it has to leak — and the harder it is to know what it touched.

Cross-border automation is, structurally, a chain of delegated access: a store agent that reads orders, a support agent that reads and replies to messages, a fulfillment agent that updates statuses — each calling tools across vendors and regions. The blast radius compounds:

The lesson from the token story is boring and durable: verify, scope, expire, log.

We keep asking whether agents are "aligned" and "safe," as if safety were a property of the model. The incidents that actually hurt people this week were all downstream of the model: a token nobody verified, a scope nobody trimmed, a credential nobody rotated.

Your agent is exactly as powerful as the identity you handed it — and exactly as dangerous as the checks you skipped on the way in. Build as if the model is trustworthy and the token is not. That's the boring posture that survives contact with production.

Verify the identity. Trim the scope. Expire the key. Log the act.

Part of a series on running a cross-border store without getting captured by it.

── more in #ai-agents 4 stories · sorted by recency
── more on @microsoft 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/your-agent-is-only-a…] indexed:0 read:2min 2026-10-01 · —