security//security misconfiguration

A security misconfiguration is a dangerous mismatch between intended policy and deployed settings: an exposed port, permissive role, mounted secret, default credential or unrestricted network path.


A security misconfiguration is a dangerous mismatch between intended policy and deployed settings: an exposed port, permissive role, mounted secret, default credential or unrestricted network path.

Agentic workloads make these mistakes unusually alive. Conventional software may never attempt the accidental path. An agent can search, inspect errors and discover that the forbidden capability is merely undocumented rather than unavailable. This does not make the agent a sophisticated attacker; it makes dormant configuration debt executable.

The system enforces configuration, not intention.