Technical writing from our assessment work on autonomous systems: how authority flows through AI agents, tools, identities, and smart-contract control planes, and what an adversary can do with it. Methodology and the artifacts we hand over, plus security findings from independent research against real open-source AI software.
What should an AI agent security assessment actually measure?
Attack success rate measures whether an agent can be manipulated. It does not describe what a deployed system lets the attacker cause once it is. This article proposes the Agent Consequence Profile, a deployment-level artifact that follows authority from the adversary's starting position through tools, memory, and enforcement points, and separates demonstrated, inferred, blocked, and untested claims.
What should an AI agent security assessment actually measure?
Duc C. Nguyen·19 min read
Agent Security
Real-world security findings
Security failures we found while evaluating real, widely adopted open-source AI and agent software. This is independent security research against public projects, not customer work, and the affected projects are not Themis customers. Several are still under coordinated disclosure, so we describe each failure and its consequence without publishing details that would locate an unpatched instance. Each finding states the affected project's public GitHub adoption, from a multi-agent framework with 9k stars to platforms above 150k stars, measured September 2026.