ஒன்று முழுமையானது, ஒன்பது பகுதியளவு, எதுவும் கண்மூடித்தனமாகக் கூறப்படவில்லை. பத்தும் முழுமையானவை என்று கூறும் பக்கம், நாங்கள் நம்பாதே என்று சொல்லும் அதே marketing ஆக இருக்கும். கீழே உள்ள coverage அளவுகள், அவற்றை மறுக்கும் வேலையை மேற்கொண்ட ஒரு தனி skeptic இடமிருந்து தப்பியவை, மேலும் ஒரு defense substrate இல் இருந்தும் deployed agent அதை இன்னும் பெறாத இடங்களில், அதை அந்த row இலேயே தெரிவிக்கிறோம்.
| அபாயம் | Coverage | CIRIS இதை எவ்வாறு நிவர்த்தி செய்கிறது |
|---|---|---|
| ASI01 Agent Goal Hijack | பகுதியளவு | பல அடுக்கு பாதுகாப்பு: import செய்யப்பட்ட skills மற்றும் messages மீது prompt-injection scanning, visual-injection isolation (conscience evaluators raw image bytes ஐ ஒருபோதும் காணாது), மற்றும் ஒரு conscience pipeline, இது ஏற்படும் ஒவ்வொரு action ஐயும் அது இயங்குவதற்கு முன் பயனரின் அசல் நோக்கத்திற்கு எதிராக மீண்டும் சரிபார்க்கிறது. குறை: input scanning pattern அடிப்படையிலானது, மீட்கப்பட்ட தரவை வழிமுறைகளிலிருந்து முறையாக பிரிக்கவில்லை. |
| ASI02 Tool Misuse | பகுதியளவு | CIRISServer, ஒரு capability-verb allow/deny பட்டியலை, server-enforced never-list உடன் வழங்குகிறது, ஒரு operation இயங்குவதற்கு முன் சரிபார்க்கப்படுகிறது, எனவே ஒரு delegated agent, அதற்கு வழங்கப்படாத ஒரு அழிவுகரமான operation ஐ invoke செய்ய முடியாது. குறிப்பு: இது இன்று fabric layer ஐப் பாதுகாக்கிறது, deployed agent இன் சொந்த LLM tool calls ஐ இன்னும் கட்டுப்படுத்தவில்லை; agent inheritance ஒரு திட்டமிடப்பட்ட கட்டம். |
| ASI03 Identity & Privilege Abuse | பகுதியளவு | substrate இல் scoped, delegated, revocable authority: signed edges இல் carry செய்யப்படும் constraints, மிக உயர்ந்த அதிகாரங்களை மீண்டும் delegate செய்வதைத் தடுக்கும் ஒரு never-list, எனவே authority escalate செய்ய முடியாது, tighten-only approval, மற்றும் உடனடி revocation. குறிப்பு: இன்று fabric இன் owner-op surface இல் நடைமுறைப்படுத்தப்படுகிறது; deployed-agent inheritance ஒரு திட்டமிடப்பட்ட கட்டம். |
| ASI04 Agentic Supply Chain | பகுதியளவு | CIRISVerify இன் post-quantum signed module manifests (முழு file-tree hash மீது Ed25519 + ML-DSA-65) மூலம் build integrity, மேலும் federated கூறுகளுக்கு signed, attested identity. குறை: இது CIRIS இன் சொந்த build மற்றும் module chain ஐ மட்டுமே உள்ளடக்குகிறது, தன்னிச்சையான third-party MCP servers ஐ அல்ல. |
| ASI05 Unexpected Code Execution | பகுதியளவு | Semantic conscience gates (entropy, coherence, optimization-veto) ஒவ்வொரு tool action இயங்குவதற்கு முன்பும் இயங்குகின்றன, நிச்சயமற்ற தன்மை ஒரு மனிதரிடம் ஒப்படைக்கப்படுகிறது. குறை: இது semantic review ஆகும், ஒரு deterministic code sandbox அல்ல. |
| ASI06 Memory & Context Poisoning | பகுதியளவு | graph memory க்கு ஒவ்வொரு எழுத்தும், ஒரு scoped, versioned graph க்குள், ஒரு அமைதியான side effect அல்ல, governed, conscience-சோதிக்கப்பட்ட action ஆகும், எனவே ஒரு poisoning write அதுவே audit செய்யக்கூடிய முடிவாகும். குறை: மீட்கப்பட்ட content இன் trust-scoring பகுதியளவே. |
| ASI07 Insecure Inter-Agent Communication | பகுதியளவு | CIRISEdge, hybrid Ed25519 + ML-DSA-65 signature verification இல் முடிவடையும் ஏழு-படி pipeline மூலம் ஒவ்வொரு inter-agent message ஐயும் சரிபார்க்கிறது (size cap, typed deserialize, schema allow-list, destination-key சோதனை, replay window). குறை: federation transport இன்னும் கட்டமைக்கப்பட்டு வருகிறது. |
| ASI08 Cascading Failures | முழுமையானது | மூன்று சுயேச்சையான அடுக்குகளில் வரம்பிடப்பட்டது: risky calls சுற்றி per-service circuit breakers (closed / open / half-open), conscience pipeline ஒரு தவறான action பரவுவதற்கு முன் அதை நிறுத்துவது, மற்றும் 50 முதல் 400 nodes வரை பூஜ்ஜிய கிராஸ்-குழு leakage என அளக்கப்பட்ட mesh isolation. |
| ASI09 Human-Agent Trust Exploitation | பகுதியளவு | conscience pipeline, ஒரு மனித reviewer பார்ப்பதற்கு முன், agent இன் சொந்த விளக்க உரையை, reviewer க்குக் காட்டப்படும் காரணத்தையும் சேர்த்து, overconfidence மற்றும் manipulation க்காக மதிப்பிடுகிறது. குறை: இது சரிபார்க்கும் அதே model family உடன் தணிக்கை செய்கிறது. |
| ASI10 Rogue Agents | பகுதியளவு | மூன்று அடுக்குகள்: ஆறு consciences ஒவ்வொரு முக்கியமான action ஐயும் அது இயங்குவதற்கு முன் கட்டுப்படுத்துகின்றன, ஒரு hash-chained signed audit trail பின்னர் மறைப்பைக் கண்டறியக்கூடியதாக ஆக்குகிறது, மற்றும் fail-secure kill switch, பெயரிடப்பட்ட மனிதர்களை ஒரு misaligned agent ஐ நிறுத்த அனுமதிக்கிறது. குறை: நுட்பமாக-misaligned ஆனால் coherent ஆன ஒரு agent ஐப் பிடிப்பது இயல்பாகவே வரம்பிடப்பட்டது. |
Agentic Applications க்கான OWASP Top 10, டிசம்பர் 2025 இல் வெளியிடப்பட்டது. ஜூலை 2026 நிலவரப்படி CIRIS உடன் mapping செய்யப்பட்டது; ஒரு cell தவறு எனில் எங்களுக்குத் தெரிவிக்கவும், நாங்கள் அதை சரிசெய்வோம்.
ஆதாரங்கள்
- ASI01 Agent Goal HijackCIRISAgent skill-import SECURITY.md + conscience pipeline
- ASI02 Tool MisuseCIRISServer auth/gate.rs + DELEGATION_CONSTRAINTS.md (shipped 0.5.72)
- ASI03 Identity & Privilege AbuseCIRISServer auth/gate.rs (never-list, tighten-only) + adoption plan
- ASI04 Agentic Supply ChainCIRISVerify Threat Model, §3.4 Supply Chain
- ASI05 Unexpected Code ExecutionCIRISAgent conscience/core.py (semantic action gates)
- ASI06 Memory & Context PoisoningCIRISAgent ciris_engine (governed graph memory)
- ASI07 Insecure Inter-Agent CommunicationCIRISEdge README (verify-before-dispatch pipeline)
- ASI08 Cascading FailuresCIRISAgent circuit_breaker.py + CIRISServer measured mesh isolation
- ASI09 Human-Agent Trust ExploitationCIRISAgent epistemic-humility conscience prompt
- ASI10 Rogue AgentsCIRISVerify HUMANITY_ACCORD kill switch + conscience pipeline
taxonomy ஒரு பார்வையே. AI பொறுப்புணர்வுக்கான ஒவ்வொரு அணுகுமுறையிலும் CIRIS எங்கு நிற்கிறது என்பதையும், kill switch எவ்வாறு சுயேச்சையாக சரிபார்க்கப்படக்கூடியது என்பதையும் காணுங்கள்.