PromptArmor’s writeup on Atlassian Rovo is a clean case study in why agent security is a capability problem, not a settings problem. The exploit is boring in the best way — and that’s exactly why it should worry anyone shipping agents into an enterprise.

I keep landing on the same lesson in production LLM ops: every tool you hand an agent is an ambient authority the model can be talked into using. Feature toggles that hide a capability from the UI while leaving the tool in the loop give teams false confidence — the HN discussion is full of people realizing their own agents have the same shape.

If your agent can construct and open URLs, assume any document it reads can address them. So which of your agent’s tools would survive being pointed at attacker-controlled input?

tags: [ agentic-ai ] [ llm-ops ] [ enterprise-ai ]