Glossary · Identity and trust

Confused deputy problem

A program holding authority is tricked into using it for a party that lacks it. Norm Hardy named it in 1988; agents acting for others face it daily.

The confused deputy problem arises when a program that holds authority, the deputy, is tricked by a less privileged party into using that authority for a purpose the authority was never meant to serve.

The original case. Norm Hardy described it in 1988 from events at Tymshare. A compiler had permission to write files in its own directory so it could update a usage-statistics file. A user who knew the name of the billing file in the same directory supplied it as the compiler’s debugging-output file, and the compiler overwrote the billing records. Hardy’s diagnosis: the compiler carried authority from two sources, its own licence and its caller’s, and had no way to say which one a given write should use. His answer was capabilities, where one reference both names an object and carries the authority to use it.

In agent systems. An agent that acts for many principals, or holds its own credentials alongside a user’s, is a deputy by design.

  • Proxies with shared credentials. MCP’s security guidance describes confused deputy attacks on MCP proxy servers that use one static OAuth client ID for every user, and requires per-client consent to prevent them. It also forbids token passthrough, because a downstream API may trust a forwarded token as if the proxy had validated it.
  • Fetching on request. A server that fetches any URL a caller supplies uses its own network position for the caller. Server-side request forgery exploits exactly that.
  • Injected instructions. Prompt injection can make an agent use its tools and credentials on behalf of whoever wrote the injected text. OWASP’s Excessive Agency entry traces the damage to excessive functionality, permissions and autonomy.

Defences. Make authority explicit per request: pass scoped, audience-restricted credentials instead of relying on a deputy’s standing permissions, and check the principal’s authority for each action. For credentials passed in-band along a chain of A2A agents, the specification recommends binding each credential to the agent that requested it, so no other agent in the chain can use it. The principle of least privilege limits what a confused deputy can do when the other defences fail.

Neighbouring terms. Delegation is the legitimate transfer of authority that a confused deputy misapplies.

Sources

  1. Norm Hardy, The Confused Deputy (or why capabilities might have been invented), Operating Systems Review 22(4), 1988 (accessed )
  2. MCP documentation: Security Best Practices (accessed )
  3. A2A Protocol Specification, section 7.6.3: In-Task Authorization Security Considerations (accessed )
  4. OWASP Top 10 for LLM Applications 2025: LLM06 Excessive Agency (accessed )