As AI systems gain increasing autonomy and execution capability, the number of discovered security vulnerabilities continues to rise. However, many of these vulnerabilities are not fundamentally novel, but instead reflect recurring classes of weaknesses long observed in prior computing systems. Execution-capable AI agents are effectively unbounded, self-modifying programs that interact extensively with multiple layers of the computing stack. This broad interaction surface imposes a significant security burden on developers, who must reason about and secure complex cross-layer behaviors. Prior research has primarily focused on vulnerabilities in open-source agents and agent frameworks. In contrast, it remains unclear whether proprietary agent systems -- developed under stricter coding standards and formal review processes -- exhibit similar security weaknesses. In this paper, we present findings from two penetration tests conducted in 2025 against proprietary agent products and evaluate whether the security posture of AI agents has improved since these assessments.
翻译:随着人工智能系统获得越来越多的自主性和执行能力,被发现的安全漏洞数量持续上升。然而,其中许多漏洞并非根本上的新颖问题,而是反映了在以往计算系统中长期存在的重复性漏洞类别。具备执行能力的AI智能体实质上是无边界、自我修改的程序,与计算栈的多个层次进行广泛交互。这种广泛的交互给开发者带来了重大的安全负担,他们必须对复杂的跨层行为进行推理并确保其安全性。以往的研究主要关注开源智能体和智能体框架中的漏洞。与之相反,尚不清楚在更严格的编码标准和正式审查流程下开发的专有智能体系统是否表现出类似的安全弱点。本文介绍了2025年针对专有智能体产品进行的两次渗透测试的结果,并评估了此次评估后AI智能体的安全态势是否有所改善。