Back to Insights

SECURING AI AGENTS · 2/3

Your AI Agent Has Your Keys. What Is It Allowed to Do?

ABRI Systems ·

You can give an assistant permission to answer messages and still be surprised by the promises it makes. That gap between technical permission and intended consent is the security problem at the centre of the Muse Marketplace story.

What the seller reported

Malwarebytes reported on September 29 that a Facebook Marketplace seller enabled Muse to handle a keyboard listing, entered his address as a pickup location and approved automatic replies. According to the seller’s account, the agent shared the address and arranged a visit without notifying him or asking separately. A buyer arrived while the seller was away. The report said Meta was investigating. Source: Pieter Arntz, Malwarebytes; original reporting: Business Insider’s account of Matt Robb’s experience.

This is a reported user experience, not a published forensic finding. It does not establish that an attacker stole a token or exploited the Mac zero-day discussed in the first article. The important detail is that the seller supplied the pickup address and enabled replies, yet did not expect the resulting disclosure and appointment.

Access does not explain intent

Authentication asks who is acting. Authorization asks what that identity may do. Consent adds the human context: which information may be shared, with whom, for what purpose, and under which conditions?

ABRI’s analysis: a broad “reply to buyers” permission leaves several decisions unresolved. May the assistant negotiate a price? Reveal a home address? Confirm that someone is available? Commit them to a time? A tool can successfully send a message while the overall interaction fails the owner’s expectations.

Make the boundary specific

A safer delegation would be: draft replies about the item, propose a price within an agreed range, and ask before confirming a meeting or revealing private contact details. The approval should show the exact recipient, message, location and time. If those details change, the approval should no longer authorize the action.

For a business, the same distinction applies to a customer-support agent. Reading a customer record need not permit sending its contents externally. Preparing a refund need not permit issuing one. These should be separate capabilities enforced by the application.

OWASP describes excessive agency as a combination of too much functionality, permission or autonomy. That framing helps teams examine the scope of delegation before an incident occurs. Source: OWASP, LLM06:2025 Excessive Agency.

What you can do today

Review automatic sending before enabling it. Start with drafts, keep private location data out of routine replies, and agree on a suitable public pickup location where appropriate. Require approval for disclosures and commitments with real consequences. Verify the agent’s notification settings and inspect its activity after a trial run.

The useful question is not simply whether an assistant has your keys. It is whether the permissions explain exactly which doors it may open.

Sources checked October 1, 2026. Incident reporting is attributed above; recommendations and analysis are ABRI’s.

Share