SCN-QUBE-002 · Observed 2025-01-17
emergingAgent Marketplace without Accountability
Qualitative signpost review · no probability assigned
Bounded observation
NIST/CAISI found that tool-using agents remained vulnerable to indirect prompt injection: across five custom injection tasks the average attack success rate was 57% on one attempt and 80% over 25 attempts. This demonstrates an accountability-relevant activation risk, but not marketplace-scale disputes or unsigned ownership chains.
Trigger threshold
Move to observed when a cross-organization agent catalog or marketplace has documented incidents involving opaque delegation, confused-deputy execution, unscoped credentials or disputed liability without effective owner and revocation metadata.
Counter-indicator
The experiments used simulated AgentDojo environments and selected attacks; they do not measure marketplace adoption, signed provenance, credential scope in production or actual loss incidence.
Update criterion
Review NIST/CAISI, incident databases and marketplace governance releases quarterly; upgrade only with attributable production incidents and downgrade if portable identity, liability and revocation controls become operational defaults.