Rainkernel

Insight

Five ways AI agents failed in production in 2026 — and the control that would have caught each

The incidents of 2026 were not model failures. They were missing controls, and almost none of them got a CVE. Here is the catalogue, mapped to the OWASP Top 10 for Agentic Applications and to the test that finds each one before go-live.

· 9 min read · Rainkernel engineering · security · agents · OWASP

By the end of 2026 the industry has, for the first time, a full catalogue of agent-specific attack classes with named victims — and a recurring pattern: the vendors' fallback was 'add a human approval', and the enterprises had no standard way to track their exposure because the incidents rarely received CVEs. The OWASP Top 10 for Agentic Applications, published for 2026, gives the classes names (ASI01 to ASI10). What follows is the five we test for first in every Agent Readiness Gate, with the control that would have caught each.

1. Indirect prompt injection through a web form (ASI01 goal hijack)

In April 2026 Capsule Security disclosed PipeLeak and ShareLeak. A malicious 'lead' submitted through a public web form was later reviewed by a Salesforce Agentforce agent, which followed the instructions embedded in the form text and emailed lead records — several, not just the one it was processing — to an external address. In Microsoft Copilot Studio, malicious SharePoint form input triggered exfiltration of customer data; the safety mechanisms flagged the attack and the data still leaked (CVE-2026-21520). The researchers noted the attack 'required no special access, no exploitation of traditional vulnerabilities, and no advanced skills'.

The control: an evaluation set that includes adversarial inputs in every untrusted channel the agent reads — forms, tickets, emails, documents — with the exfiltration paths (email, HTTP, file write) as the measured outcome. Human approval on email actions, the vendors' mitigation, is a stopgap; a tested guardrail is a control.

2. Tool-description poisoning (ASI02 tool misuse, ASI04 supply chain)

The MCPTox benchmark measured tool-description poisoning across 45 live MCP servers and 20 models: an average attack success rate of 36.5%, with the worst model following poisoned descriptions 72.8% of the time. The Cloud Security Alliance's July 2026 note is blunt — the protocol 'lacks mandatory client-side validation or cryptographic verification of tool descriptions'. The MCP 2026-07-28 specification added a deterministic tools list and identity, but not signing or provenance.

The control: hash-pin every approved tool definition and re-verify continuously; scan descriptions for instruction payloads with the open-source scanners (snyk-agent-scan, Cisco mcp-scanner) before approval; include tool-poisoning cases in the attack pack. This is what MCPSentry exists to do continuously.

3. Context-file poisoning and the first agent worm (ASI06 memory and context poisoning)

In June 2026 the Miasma worm propagated through AI coding-agent configuration files — .claude/settings.json, .gemini/settings.json, .cursor/rules, .vscode/tasks.json — harvesting developer credentials and reaching 73 Microsoft repositories across four GitHub organisations without touching a package registry. Separately, Snyk's analysis of 3,984 agent skills found 36.8% flawed and a concurrent typosquatting campaign placed hundreds of malicious skills in a public hub.

The control: treat SKILL.md, CLAUDE.md, AGENTS.md and editor task files as supply chain: scan them, pin them, and include context-poisoning cases in the evaluation harness. The permission audit asks what a poisoned agent could reach — which is the question that decides blast radius.

4. Cost amplification and runaway loops (ASI08 cascading failures)

Mandiant's $50,000-in-an-hour accounting agent is the headline; the research behind it is a January 2026 paper showing that a compromised tool server can inflate a single query's cost by up to 658× purely by inducing repetitive tool calls. Cloud billing alerts arrive about a day later. No attacker is needed — a timeout and a persistent planner are enough.

The control: a cost-per-task baseline measured on real traffic before go-live, step and depth caps, and a server-side circuit breaker. The Gate measures the baseline; the Agent Cost Governor enforces the ceiling.

5. Over-permissioned agents (ASI03 identity and privilege abuse)

Seventy-four percent of organisations say their agents are over-permissioned and more than two-thirds cannot distinguish an agent's actions from a human's (CSA and Aembit, March 2026). Gartner's 30 September 2026 guidance for CISOs found 54% of organisations have no approach to limiting agent access at all. The DN42 case from May 2026 shows the consequence: an autonomous agent with full cloud access provisioned five large instances, load balancers and functions, repeatedly, for a workload that needed a $5-a-month server.

The control: a permission and identity audit — over-access, shared accounts, rotation, decommissioning — with per-agent accounts and kill switches, and an Agent Bill of Materials so the inventory exists before procurement or an insurer asks for it.

The common thread

None of these failures was a model being insufficiently clever. Each was an untested assumption: that form input is data, that a tool description is static, that a config file is config, that a loop ends, that an agent needs what it has. Only 37% of teams run online evaluations, although 89% have observability — so the failures were watched in detail and prevented by nobody.

The Agent Readiness Gate runs the attack pack for all five classes, seeds an evaluation harness from the agent's own failures, baselines the cost per task, audits the permissions and emits the BOM — in two weeks, inside your cloud, at a published price. The product page has the detail; the free Readiness Score tells you in two minutes which of the five would stall you first.

Sources

  1. OWASP Top 10 for Agentic Applications 2026
  2. Dark Reading: Microsoft and Salesforce patch AI agent data-leak flaws, 15 April 2026
  3. Capsule Security: PipeLeak — exploiting Salesforce Agentforce with indirect prompt injection
  4. Cloud Security Alliance: MCP tool poisoning and auto-execution, 1 July 2026
  5. Model Context Protocol specification 2026-07-28 changelog
  6. The Hacker News: Miasma worm hits 73 Microsoft GitHub repositories, June 2026
  7. Snyk: ToxicSkills — malicious AI agent skills
  8. Cloud Security Alliance: SKILL.md agent context poisoning, 6 May 2026
  9. Help Net Security: Google Mandiant enterprise AI security risks report, 16 September 2026
  10. Tech Times: tool-call attack inflates agent costs 658×, 14 June 2026
  11. Cloud Security Alliance and Aembit survey, 24 March 2026
  12. Gartner: top five actions for CISOs by end of 2026, 30 September 2026
  13. InfoQ: AI agents and billing guardrails, 16 July 2026
  14. LangChain: State of Agent Engineering 2026

Statistics are quoted from the sources above and remain the work of their authors. Single-source accounts are labelled as such. Corrections: hello@rainkernel.com.

Tell us the use case. We'll tell you where it would stall.

A 30-minute call, no deck, no charge. You leave with an honest read on production readiness and, if it fits, a fixed-price proposal within 48 hours.