Join our Newsletter — 33% off our NHI Course
Agentic AI & Autonomous Identity

Agentic worm

← Back to Glossary
By NHI Mgmt Group Updated October 7, 2026 Domain: Agentic AI & Autonomous Identity

A hypothetical malware pattern in which one AI agent can cause another to run malicious or unsafe prompts, spreading behavior through inter-agent communication rather than through classic self-replication alone. The risk is recursive propagation through legitimate delegation and tool-use pathways.

What makes an agentic worm different from classic malware?

An agentic worm does not need to self-replicate in the traditional sense. Instead, it spreads by persuading or inducing one autonomous agent to hand off unsafe prompts, instructions, or delegated actions to another agent through normal collaboration paths.

That matters because the propagation mechanism is social and procedural as much as technical. The worm can ride on legitimate inter-agent communication, tool calls, shared context, and approval workflows, which makes the behaviour harder to spot than a conventional payload that simply copies itself.

It also changes the attacker’s objective. Rather than exploiting a single host or process, the malicious pattern aims to contaminate an agent ecosystem, where one compromised interaction can cascade into many downstream actions if agents trust each other too readily.

How agentic worms propagate across agent systems

The spread path is usually recursive. A compromised or manipulated agent sends a prompt, task, or message that causes the next agent to execute unsafe instructions, copy the bad context forward, or expose additional tools and permissions.

This can happen through multi-agent orchestration, delegated tool use, shared memory, or chained workflows. A system that treats messages as trustworthy by default gives the attacker an efficient propagation channel, especially when each agent has enough authority to act on the next step without human review.

For background on the wider agent security model, the distinction between autonomous systems, delegated authority, and identity-aware controls is laid out in AI Agents vs Agentic AI and Agentic AI Identity Guide.

Why trust boundaries fail in agentic worm scenarios

Agentic worms exploit the assumption that an upstream agent is a safe and competent sender. If the receiving agent does not validate intent, scope, or provenance, it may treat malicious instructions as a normal handoff and continue the chain.

The real weakness is not only prompt content, but the absence of strong boundaries around what an agent may accept, forward, or execute on behalf of another actor. Once that trust is embedded in inter-agent communication, the malicious behaviour can spread without the visible markers that usually accompany malware infection.

Architectures that rely on agent-to-agent delegation should treat every handoff as a policy decision. Multi-Agent and A2A Security Guide is useful because it focuses on authentication, signed agent cards, and multi-hop delegation, all of which directly affect whether a worm can propagate.

Where containment and governance matter most

Agentic worm behaviour becomes most dangerous when agents have broad tool access, weak approval gates, or shared memory that allows one compromised interaction to influence many later decisions. The practical issue is blast radius: a single unsafe chain can turn into repeated execution across agents, environments, or tenants.

That is why containment needs to be designed into the agent fabric itself, not added after the fact. Limiting delegation scope, separating contexts, and making tool invocation explicit reduce the chance that one agent can convert a malicious instruction into a reusable propagation pattern.

For operational containment, the most directly relevant guidance is Agentic AI Security Guide, which maps agent threats to controls across inputs, memory, tools, orchestration, and identity.

Risk and Threat Considerations

Agentic worms are risky because they turn trusted collaboration into an attack path. The danger is not only compromise of one agent, but the possibility that malicious prompts, delegated actions, or poisoned context will propagate repeatedly through otherwise legitimate workflows.

Failure mechanism: One agent accepts or forwards unsafe instructions without validating intent, provenance, or scope, then passes the same harmful context or action chain to other agents with enough authority to continue the spread.

Impact: Attackers can trigger recursive execution, widen blast radius, harvest tools or secrets exposed to downstream agents, and create a contamination pattern that looks like normal automation unless the workflow is instrumented and bounded.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI07 — Insecure Inter-Agent CommunicationAgentic worms spread through inter-agent message handling and delegation.
ASI03 — Identity & Privilege AbuseRecursive spread depends on abused agent authority and overbroad access.
ASI08 — Cascading FailuresA worm-like chain creates downstream failure across multiple linked agents.
Recommendation — Harden inter-agent channels to prevent unsafe propagation between agents. Restrict agent privilege so one compromised agent cannot amplify access. Design containment so one agent failure cannot cascade across the fleet.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeLimiting agent permissions reduces the impact of recursive misuse.
Recommendation — Apply least privilege to each agent and its delegated tools.

Practitioner Guidance

What to watch for: Treat agent handoffs as security boundaries. The key judgement is whether the receiving agent is allowed to trust, transform, or execute what the previous agent passed along without an independent policy check.

Design for narrow delegation, explicit approval where action is material, and clear separation between read, reason, and act steps. If a workflow would be unsafe when copied across several agents, it is already too permissive for agentic use.

Practitioner takeaway: The most effective control against an agentic worm is to make every inter-agent transfer verifiable, scoped, and revocable before the next agent is allowed to act.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 7, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org