Skip to content

Attack Surface Proliferation in Agentic AI: How Tool Calls, Memory Persistence, Skill Ecosystems, and Payment Rails Compose Into a Systemic Threat

Sep 2026 · Zenodo (CERN European Organization for Nuclear Research)

Abstract

This version (2026-09-26) corrects a citation error found by an automated check and confirmed by hand against the arXiv abstracts. Version 2 cited the identifier 2605.30998 for the ClawTrojan multi-step trojan benchmark and its DASGuard defense; that identifier is a security analysis of x402 payments, and ClawTrojan is arXiv:2605.31042. All six trojan citations are corrected. The x402 payment-layer claims keep arXiv:2605.30998, which is right for them, and the version 2 caveats warning that the two topics shared one identifier are replaced with what that paper's abstract reports. An unsupported phrase ("or redirect funds") and a pointer to internal drafting instructions are removed. The thesis is unchanged. This version has not had a full claim-by-claim audit. The full list of corrections is at the top of the PDF. The deployment of large language model (LLM) agents into production environments has outpaced the security frameworks designed to contain them. This paper argues a candidate structural pattern worth investigating: the attack surface of agentic AI systems is not additive across components but compositional, meaning that tool invocation, persistent memory, third-party skill ecosystems, and machine-to-machine payment rails each introduce independent vulnerabilities that compound when combined in a single agent harness. This is a heuristic reading, not a formal derivation; the mechanism we identify is the chaining of trust assumptions across subsystems that were designed and evaluated independently. We synthesize findings from seven recent preprints spanning cs.CR, covering: speculative tool-call privacy leakage before commitment arXiv:2606.02483, indirect prompt injection through enterprise SaaS integrations arXiv:2606.02240, multi-step trojan persistence in local agentic workspaces arXiv:2605.31042, memory poisoning via dialogue interaction arXiv:2605.29960, skill marketplace malware distribution arXiv:2605.28588, machine-to-machine payment protocol vulnerabilities in x402 arXiv:2605.30998, and coordinated multi-agent sabotage arXiv:2605.29178. A supplementary source on attribute-based access control for tool-use agents arXiv:2605.28071 provides a candidate defense framing. The attacker model throughout is a motivated external adversary with read access to at least one integration endpoint or skill marketplace listing, who exploits the trust transitivity inherent in composed agentic pipelines. The primary falsification path: if deploying layered, cross-subsystem monitoring (covering speculative calls, skill ingestion, memory writes, and payment state) reduces the compound attack success rate to that of the weakest single-subsystem baseline, the compositionality claim fails and the threat is merely additive. Authorship: Saluca Agentic AI Research Team (Saluca LLC). AI-drafted synthesis from an arXiv preprint corpus, originally drafted 2026-06-03, produced under the direction of Cristian Ruvalcaba, the accountable human author. Not peer-reviewed. AI disclosure. This work was produced with an agentic AI research apparatus operated by Saluca Labs. The apparatus drafted, searched and analysed under direction. Cristian Ruvalcaba is the human author and is accountable for the content. No AI system is listed as an author or contributor, because authorship entails accountability that a model cannot hold; this disclosure is the credit, and it is deliberately the whole of it.

View source

Similar papers

#computer vision Open access Jun 2016

Software Development in Startup Companies: The Greenfield Startup Model

The results are packaged in the Greenfield Startup Model (GSM), which explains the priority of startups to release the product as quickly as possible, and the need to shorten time-to-market, by speeding up the development through low-precision engineering activities.

Carmine Giardino, Nicolò Paternoster, M. Unterkalmsteiner et al. · 178 citations · ⚡14
#computer vision Open access Oct 2016

Software Startups - A Research Agenda

Software startup companies develop innovative, software-intensive products within limited timeframes and with few resources, searching for sustainable and scalable business models.

M. Unterkalmsteiner, P. Abrahamsson, Xiaofeng Wang et al. · 157 citations · ⚡17
#machine learning Review Open access Oct 2016

“Failures” to be celebrated: an analysis of major pivots of software startups

This study conducts a case survey study based on the secondary data of the major pivots happened in 49 software startups, and demonstrates that customer need pivot is the most common among all pivot types.

Sohaib Shahid Bajwa, Xiaofeng Wang, Anh Nguyen-Duc et al. · 127 citations · ⚡15
#computer vision Review Open access May 2015

A survey study on major technical barriers affecting the decision to adopt cloud services

The comparison of adopter and non-adopter sample reveals three potential adoption inhibitor, security, data privacy, and portability, which underlines the importance of the technical and security perspectives for research investigating the adoption of technology.

Nattakarn Phaphoom, Xiaofeng Wang, S. Samuel et al. · 111 citations · ⚡8
#computer vision Conference Open access Dec 2013

Affordable and Energy-Efficient Cloud Computing Clusters: The Bolzano Raspberry Pi Cloud Cluster Experiment

The ongoing work building a Raspberry Pi cluster consisting of 300 nodes is presented, with potential use cases being an inexpensive and green test bed for cloud computing research and a robust and mobile data center for operating in adverse environments.

P. Abrahamsson, S. Helmer, Nattakarn Phaphoom et al. · 110 citations · ⚡7
#computer vision Book Open access Mar 2017

On the Unhappiness of Software Developers

The results indicate that software developers are a slightly happy population, but the need for limiting the unhappiness of developers remains, and 219 factors representing causes of unhappiness while developing software are identified.

D. Graziotin, Fabian Fagerholm, Xiaofeng Wang et al. · 84 citations · ⚡6

Related blog posts

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.