Search papers, labs, and topics across Lattice.
This paper introduces the concept of the agentic posture vulnerability (APV) as a framework for managing persistent vulnerabilities in AI coding agents that arise from gaps between mandate and authority. By linking various runtime manifestations of agent behavior to a consistent posture, the APV approach allows for better tracking and management of risks associated with excessive agency and inadequate controls. The authors provide practical tools and a research agenda to operationalize this framework, distinguishing it from traditional vulnerability classifications like CVEs and OWASP guidelines.
Persistent vulnerabilities in AI agents can be effectively managed through a novel framework that links agent behavior to a consistent control posture.
Existing guidance identifies excessive agency, excessive permission, weak task-bound authorization, and inadequate agent controls as important risks. Control frameworks also describe capabilities for constraining, authorizing, observing, validating, and responding to agent activity. Yet security programs still need a way to manage persistent deployed instances that span components and outlive any one event. We propose the agentic posture vulnerability (APV) as a task-conditioned vulnerability-management abstraction: a durable record for a composed agent-control exposure. One posture may produce different runtime manifestations across tasks; APV links those manifestations to the invariant posture and remains open until authority is narrowed, a missing control is added, risk is accepted, or closure is verified. APV is not proposed as a new root-cause class of risk; it operationalizes existing excessive-agency, authorization, and control-composition weaknesses. We distinguish APVs from CVE-addressable product defects, OWASP Excessive Agency, Agent Baseline control outcomes, and the runtime authorization-execution gap. We then provide a field vignette, a thresholded definition, six recurring APV patterns, a vulnerability lifecycle, a minimum record, a control-and-closure matrix, tooling implications, and a testable research agenda.