Unverified agent execution

A successful tool response is treated as proof that the intended system state changed.

01 / Attack path

How the boundary is crossed

A firewall tool returns HTTP 200 for a rule update, but the edge devices never receive the policy.

Attack path and interception point
  1. 01Lower-trust input
  2. 02Attempted instruction
  3. 03Protected action
  4. 04Enforced decision

02 / Containment

Where bounded authority limits the effect

Bind decision and executor receipt to an independent read of the authoritative firewall state after propagation.

03 / Failure and evidence

The attacker’s opportunity and the defender’s record

Exploit condition

An agent reports protection complete while the old rule remains active.

Evidence to retain

Record tool response, observation source and time, mismatch and remediation status.

04 / Canonical scope

Why this reference stands alone

False-success evidence concerns a misleading record; this page owns missing outcome verification.

Protocol or attack trace

False-completion check

Sequence

Firewall tool returns HTTP 200; effective edge rule remains old after propagation window.

Negative test

Mark result partial or unknown until authoritative edge read shows new rule.

Primary references

Read the underlying material

Architecture discussion

Choose one consequential action and make its boundary explicit.

Request a Conversation