Hack an AI Agent Live: When AI Trusts AI
One AI agent trusts what the last one told it. Watch what happens when an attacker sits in that gap and rides the trust chain into a real business action.
Poisoned context enters upstream. A legitimate downstream agent carries the attacker's intent.
- ✓ A real agent-to-agent prompt injection, demonstrated live against a sequential workflow
- ✓ How a rogue agent clears a superficial AI verification check and moves malicious context downstream
- ✓ Practical defenses: provenance checks, least privilege, constrained tools, human approval for high-impact actions
With Kevin King, Director of Integrated Learning, EC-Council. 20 years in offensive security.
Inside the session
A live look at the attack surface no one is testing
As autonomous agents get wired into enterprise workflows, the trust between agents, tools, data sources, and the business actions they trigger is becoming one of the least understood attack surfaces in security. Kevin King runs the attack end to end, then goes past the injection itself to the real failure underneath: excessive transitive trust combined with automated authority.
How prompt injection propagates across a multi-agent workflow instead of staying trapped in one chatbot or model.
Where the dangerous trust boundaries sit: between AI agents, external data sources, tools, APIs, and downstream business actions.
Why proof of intelligence or protocol compliance is not proof of identity, authorization, integrity, or trustworthiness.
How poisoned upstream context steers otherwise legitimate downstream agents into unauthorized outcomes.
The defenses that shrink the blast radius: provenance checks, least privilege, constrained tool permissions, independent validation, and human approval for high-impact actions.

Speaker
Kevin King
Director of Integrated Learning, EC-Council
A nationally recognized technical instructor and consultant with more than 20 years in cybersecurity and ethical hacking. In this session he runs the agent-to-agent attack in real time, walks through each trust boundary as it breaks, and shows how to build the checks that stop a poisoned agent from turning into an unauthorized business action.
Also covered
Live attendees enter for a C|OASP certification bundle
One engaged attendee walks away with full access to a C|OASP bundle. Stay active through the session for your chance to be selected.
Why FireCompass is in the room
FireCompass builds agentic offensive security. Testing how agents, tools, and APIs behave under a real attacker is the daily work, which is why the trust boundaries in this session matter to us as much as they will to you. AI safety and governance for autonomous systems is not a slide at the end. It is the design problem.
Seats are limited. The demo is live and one-time.
Register once. We'll send the join link and a calendar hold.
Save my seat →July 30, 2026 · 1:00 PM EDT / 10:00 AM PDT / 10:30 PM IST