Common questions.
What is Agent Hijacking?
Agent hijacking is the takeover of an active AI agent session by an attacker, allowing them to redirect the agent's actions, extract its credentials, or use it as a proxy to access protected systems.
How does Agent Hijacking work?
It can occur through session token theft, MCP transport interception, or exploitation of insufficient authentication in the agent's control interface.
Which terms are related to Agent Hijacking?
Closely related concepts include Agent Retirement, Access Token, Agent Card, Agent Passport. Each is defined in the Prefactor glossary.