Attack Surface Proliferation in Agentic AI: How Tool Calls, Memory Persistence, Skill Ecosystems, and Payment Rails Compose Into a Systemic Threat
Abstract
This version (2026-09-26) corrects a citation error found by an automated check and confirmed by hand against the arXiv abstracts. Version 2 cited the identifier 2605.30998 for the ClawTrojan multi-step trojan benchmark and its DASGuard defense; that identifier is a security analysis of x402 payments, and ClawTrojan is arXiv:2605.31042. All six trojan citations are corrected. The x402 payment-layer claims keep arXiv:2605.30998, which is right for them, and the version 2 caveats warning that the two topics shared one identifier are replaced with what that paper's abstract reports. An unsupported phrase ("or redirect funds") and a pointer to internal drafting instructions are removed. The thesis is unchanged. This version has not had a full claim-by-claim audit. The full list of corrections is at the top of the PDF. The deployment of large language model (LLM) agents into production environments has outpaced the security frameworks designed to contain them. This paper argues a candidate structural pattern worth investigating: the attack surface of agentic AI systems is not additive across components but compositional, meaning that tool invocation, persistent memory, third-party skill ecosystems, and machine-to-machine payment rails each introduce independent vulnerabilities that compound when combined in a single agent harness. This is a heuristic reading, not a formal derivation; the mechanism we identify is the chaining of trust assumptions across subsystems that were designed and evaluated independently. We synthesize findings from seven recent preprints spanning cs.CR, covering: speculative tool-call privacy leakage before commitment arXiv:2606.02483, indirect prompt injection through enterprise SaaS integrations arXiv:2606.02240, multi-step trojan persistence in local agentic workspaces arXiv:2605.31042, memory poisoning via dialogue interaction arXiv:2605.29960, skill marketplace malware distribution arXiv:2605.28588, machine-to-machine payment protocol vulnerabilities in x402 arXiv:2605.30998, and coordinated multi-agent sabotage arXiv:2605.29178. A supplementary source on attribute-based access control for tool-use agents arXiv:2605.28071 provides a candidate defense framing. The attacker model throughout is a motivated external adversary with read access to at least one integration endpoint or skill marketplace listing, who exploits the trust transitivity inherent in composed agentic pipelines. The primary falsification path: if deploying layered, cross-subsystem monitoring (covering speculative calls, skill ingestion, memory writes, and payment state) reduces the compound attack success rate to that of the weakest single-subsystem baseline, the compositionality claim fails and the threat is merely additive. Authorship: Saluca Agentic AI Research Team (Saluca LLC). AI-drafted synthesis from an arXiv preprint corpus, originally drafted 2026-06-03, produced under the direction of Cristian Ruvalcaba, the accountable human author. Not peer-reviewed. AI disclosure. This work was produced with an agentic AI research apparatus operated by Saluca Labs. The apparatus drafted, searched and analysed under direction. Cristian Ruvalcaba is the human author and is accountable for the content. No AI system is listed as an author or contributor, because authorship entails accountability that a model cannot hold; this disclosure is the credit, and it is deliberately the whole of it.