Breaking the Paperclip
Three critical vulnerabilities in AI agent orchestration reveal the same pattern. Self-registration enabled code execution. DNS rebinding crossed loopback boundaries. Ungated endpoints exposed data. Each failure relied on a different implicit trust assumption. Each one exploited the same execution sink: agent configuration treated as trusted input.
Agent platforms blur the line between configuration and execution. Configuration is code. Whoever controls it controls what runs. This isn't a vendor bug; it's how agentic systems fail at scale. As agents proliferate across enterprise infrastructure, security teams need visibility into what's running, who authorized it, and how to govern it before it becomes shadow access.
Download the full technical report for:
- Attack chains and reproduction paths you can test immediately
- Why Paperclip's fixes work and what your platforms need
- Four capabilities for Agentic Access Management that actually scale



