Agentic Terminology | Episode 64
E64

Agentic Terminology | Episode 64

In this episode of BHIS Presents: AI Security Ops, the team tackles one of the biggest sources of confusion in modern AI:

What’s the difference between prompts, skills, tools, memory, and sub-agents?

These terms are everywhere in discussions about agentic AI. They’re often used interchangeably—but they describe very different capabilities. More importantly, each one introduces its own unique security risks.

If you’re building, deploying, or securing AI agents, understanding this vocabulary isn’t just helpful. It’s essential.

Because every new capability an agent gains is also a new attack surface.

We break down each core building block of agentic systems, explain what it actually does, and discuss how attackers can abuse it—from prompt injection and memory poisoning to supply-chain attacks and excessive tool permissions.

We dig into:
- The difference between prompts, skills, tools, memory, and sub-agents
- Why prompts define behavior but don’t create lasting capability
- How skills package reusable expertise without granting new permissions
- Why tools are what allow AI agents to take real-world actions
- The security risks of giving agents excessive privileges
- How prompt injection remains the biggest threat facing AI agents today
- Why memory transforms a one-time attack into a persistent compromise
- How memory poisoning can influence future conversations
- Why sub-agents improve scalability while creating new trust boundaries
- The dangers of delegation, confused deputies, and poisoned summaries
- Why every new capability increases an agent’s attack surface
- How applying least privilege dramatically reduces AI security risk

This episode explores one of the most important mental models in agentic AI: think of an AI agent like a new employee.

The prompt is the job description.

Skills are the documented procedures.

Tools are the systems they’re allowed to access.

Memory is their notebook.

Sub-agents are the coworkers they delegate work to.

Every one of those components makes an agent more capable—and every one creates new opportunities for something to go wrong.

The takeaway: don’t evaluate an AI agent by how intelligent it is. Evaluate what it can access, what it can change, what it remembers, and who it trusts.



Chapters

0:00 – Intro: Understanding Agentic AI Terminology
1:18 – Prompts: Instructions and Prompt Injection
3:18 – Skills: Reusable Knowledge and Supply Chain Risk
5:18 – Tools: Permissions, Actions, and Least Privilege
7:40 – Memory: Persistence and Memory Poisoning
10:08 – Sub-Agents: Delegation and Trust Chains
12:18 – Putting It All Together: Expanding Attack Surface
14:05 – Final Takeaways



Key Concepts & Topics

Prompts
- System prompts vs. user prompts
- Temporary instructions
- Prompt injection attacks
- Trusted vs. untrusted inputs

Skills
- Reusable task expertise
- On-demand procedural knowledge
- Context efficiency
- Supply-chain trust

Tools
- External capabilities
- Email, web search, databases, and code execution
- Permission boundaries
- Least privilege

Memory
- Persistent context
- Long-term personalization
- Memory poisoning
- Privacy and data protection

Sub-Agents
- Task delegation
- Isolated context windows
- Confused deputy attacks
- Trust boundaries

Agent Security
- Expanding attack surface
- Capability versus risk
- Secure agent design
- Defense-in-depth for AI systems

Learn more about Black Hills Information Security:
https://www.blackhillsinfosec.com/

Check out Antisyphon Training:
https://www.antisyphontraining.com/

#AISecurity #CyberSecurity #LLMSecurity #ArtificialIntelligence #AgenticAI #AIAgents #PromptInjection #InfoSec #BHIS #Antisyphon

  • (00:00) - Intro: Understanding Agentic AI Terminology
  • (01:28) - Prompts: Instructions and Prompt Injection
  • (07:00) - Skills: Reusable Knowledge and Supply Chain Risk
  • (11:55) - Tools: Permissions, Actions, and Least Privilege
  • (14:50) - Memory: Persistence and Memory Poisoning
  • (22:54) - Sub-Agents: Delegation and Trust Chains
  • (26:52) - Putting It All Together: Expanding Attack Surface
  • (27:58) - Final Takeaways

Click here to watch this episode on YouTube.


Brought to you by:
Black Hills Information Security 

☯️ Introducing BHIS Fusion Penetration Testing
https://www.blackhillsinfosec.com/fusion-penetration-testing/

Antisyphon Training

Active Countermeasures

Wild West Hackin Fest
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits
https://poweredbybhis.com


Episode Video

Creators and Guests

Brian Fehrman
Host
Brian Fehrman
Brian Fehrman is a long-time BHIS Security Researcher and Consultant with extensive academic credentials and industry certifications who specializes in AI, hardware hacking, and red teaming, and outside of work is an avid Brazilian Jiu-Jitsu practitioner, big-game hunter, and home-improvement enthusiast.
Bronwen Aker
Host
Bronwen Aker
Bronwen Aker is a BHIS Technical Editor who joined full-time in 2022 after years of contract work, bringing decades of web development and technical training experience to her roles in editing pentest reports, enhancing QA/QC processes, and improving public websites, and who enjoys sci-fi/fantasy, Animal Crossing, and dogs outside of work.
Derek Banks
Host
Derek Banks
Derek is a BHIS Security Consultant, Penetration Tester, and Red Teamer with advanced degrees, industry certifications, and broad experience across forensics, incident response, monitoring, and offensive security, who enjoys learning from colleagues, helping clients improve their security, and spending his free time with family, fitness, and playing bass guitar.