SIGNAL//DESK
AI securitysrc: MITRE ATLAS

Local AI Agent

A local AI agent is a digital assistant running directly on your computer that has the power to click buttons, open files, and use apps just like you do. Because it has these 'human' permissions, if a hacker tricks the AI, they can use it as a puppet to take full control of your entire computer.

A local AI agent is an autonomous software entity operating within a host environment, granted high-privilege access to system APIs, file systems, and browser interfaces to perform complex workflows. Security risks arise because the agent's broad execution permissions serve as a proxy; if an adversary compromises the agent's instruction set or input stream, they inherit the agent's system-level authority to execute arbitrary code and exfiltrate data.

A local AI agent is a high-privilege autonomous process integrated into the host operating system, designed to interact with system-level APIs, applications, and external services via broad, often persistent, authorization tokens. From a security perspective, the agent functions as a privileged execution vector; successful adversarial manipulation of the agent's reasoning loop or input context allows for the escalation of privileges to the agent's security context, enabling full system compromise, arbitrary command execution, and persistence mechanisms.


← all terms