Skip to content
Artwork for AI Security Ops
AI Security Ops · July 31 · 28 min

Agentic Terminology | Episode 64

In this episode of BHIS Presents: AI Security Ops, the team tackles one of the biggest sources of confusion in modern AI: What’s the difference between prompts, skills, tools, memory, and sub-agents? These terms are everywhere in discussions about agentic AI. They’re often used interchangeably—but they describe very different capabilities. More importantly, each one introduces its own unique security risks. If you’re building, deploying, or securing AI agents, understanding this vocabulary isn’t just helpful. It’s essential. Because every new capability an agent gains is also a new attack surface. We break down each core building block of agentic systems, explain what it actually does, and discuss how attackers can abuse it—from prompt injection and memory poisoning to supply-chain attacks and excessive tool permissions. We dig into: - The difference between prompts, skills, tools, memory, and sub-agents - Why prompts define behavior but don’t create lasting capability - How skills package reusable expertise without granting new permissions - Why tools are what allow AI agents to take real-world actions - The security risks of giving agents excessive privileges - How prompt injection remains the biggest threat facing AI agents today - Why memory transforms a one-time attack into a persistent compromise - How memory poisoning can influence future conversations - Why sub-agents improve scalability while creating new trust boundaries - The dangers of delegation, confused deputies, and poisoned summaries - Why every new capability increases an agent’s attack surface - How applying least privilege dramatically reduces AI security risk This episode explores one of the most important mental models in agentic AI: think of an AI agent like a new employee. The prompt is the job description. Skills are the documented procedures. Tools are the systems they’re allowed to access. Memory is their notebook. Sub-agents are the coworkers they delegate work to. Every one of those components makes an agent more capable—and every one creates new opportunities for something to go wrong. The takeaway: don’t evaluate an AI agent by how intelligent it is. Evaluate what it can access, what it can change, what it remembers, and who it trusts. — Chapters 0:00 – Intro: Understanding Agentic AI Terminology 1:18 – Prompts: Instructions and Prompt Injection 3:18 – Skills: Reusable Knowledge and Supply Chain Risk 5:18 – Tools: Permissions, Actions, and Least Privilege 7:40 – Memory: Persistence and Memory Poisoning 10:08 – Sub-Agents: Delegation and Trust Chains 12:18 – Putting It All Together: Expanding Attack Surface 14:05 – Final Takeaways — Key Concepts & Topics Prompts - System prompts vs. user prompts - Temporary instructions - Prompt injection attacks - Trusted vs. untrusted inputs Skills - Reusable task expertise - On-demand procedural knowledge - Context efficiency - Supply-chain trust Tools - External capabilities - Email, web search, databases, and code execution - Permission boundaries - Least privilege Memory - Persistent context - Long-term personalization - Memory poisoning - Privacy and data protection Sub-Agents - Task delegation - Isolated context windows - Confused deputy attacks - Trust boundaries Agent Security - Expanding attack surface - Capability versus risk - Secure agent design - Defense-in-depth for AI systems Learn more about Black Hills Information Security: https://www.blackhillsinfosec.com/ Check out Antisyphon Training: https://www.antisyphontraining.com/ #AISecurity #CyberSecurity #LLMSecurity #ArtificialIntelligence #AgenticAI #AIAgents #PromptInjection #InfoSec #BHIS #Antisyphon (00:00) - Intro: Understanding Agentic AI Terminology (01:28) - Prompts: Instructions and Prompt Injection (07:00) - Skills: Reusable Knowledge and Supply Chain Risk (11:55) - Tools: Permissions, Actions, and Least Privilege (14:50) - Memory: Persistence and Memory Poisoning (22:54) - Sub-Agents: Delegation and Trust Chains (26:52) - Putting It All Together: Expanding Attack Surface (27:58) - Final Takeaways Click here to watch this episode on YouTube. Creators & Guests Brian Fehrman - Host Bronwen Aker - Host Derek Banks - Host Brought to you by: Black Hills Information Security https://www.blackhillsinfosec.com ☯️ Introducing BHIS Fusion Penetration Testing https://www.blackhillsinfosec.com/fusion-penetration-testing/ Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.com Click here to view the episode transcript.

0:00-28:31

transcript

No transcript — this publisher did not publish one.

show notes

In this episode of BHIS Presents: AI Security Ops, the team tackles one of the biggest sources of confusion in modern AI:

What’s the difference between prompts, skills, tools, memory, and sub-agents?

These terms are everywhere in discussions about agentic AI. They’re often used interchangeably—but they describe very different capabilities. More importantly, each one introduces its own unique security risks.

If you’re building, deploying, or securing AI agents, understanding this vocabulary isn’t just helpful. It’s essential.

Because every new capability an agent gains is also a new attack surface.

We break down each core building block of agentic systems, explain what it actually does, and discuss how attackers can abuse it—from prompt injection and memory poisoning to supply-chain attacks and excessive tool permissions.

We dig into:
- The difference between prompts, skills, tools, memory, and sub-agents
- Why prompts define behavior but don’t create lasting capability
- How skills package reusable expertise without granting new permissions
- Why tools are what allow AI agents to take real-world actions
- The security risks of giving agents excessive privileges
- How prompt injection remains the biggest threat facing AI agents today
- Why memory transforms a one-time attack into a persistent compromise
- How memory poisoning can influence future conversations
- Why sub-agents improve scalability while creating new trust boundaries
- The dangers of delegation, confused deputies, and poisoned summaries
- Why every new capability increases an agent’s attack surface
- How applying least privilege dramatically reduces AI security risk

This episode explores one of the most important mental models in agentic AI: think of an AI agent like a new employee.

The prompt is the job description.

Skills are the documented procedures.

Tools are the systems they’re allowed to access.

Memory is their notebook.

Sub-agents are the coworkers they delegate work to.

Every one of those components makes an agent more capable—and every one creates new opportunities for something to go wrong.

The takeaway: don’t evaluate an AI agent by how intelligent it is. Evaluate what it can access, what it can change, what it remembers, and who it trusts.

Chapters

0:00 – Intro: Understanding Agentic AI Terminology
1:18 – Prompts: Instructions and Prompt Injection
3:18 – Skills: Reusable Knowledge and Supply Chain Risk
5:18 – Tools: Permissions, Actions, and Least Privilege
7:40 – Memory: Persistence and Memory Poisoning
10:08 – Sub-Agents: Delegation and Trust Chains
12:18 – Putting It All Together: Expanding Attack Surface
14:05 – Final Takeaways

Key Concepts & Topics

Prompts
- System prompts vs. user prompts
- Temporary instructions
- Prompt injection attacks
- Trusted vs. untrusted inputs

Skills
- Reusable task expertise
- On-demand procedural knowledge
- Context efficiency
- Supply-chain trust

Tools
- External capabilities
- Email, web search, databases, and code execution
- Permission boundaries
- Least privilege

Memory
- Persistent context
- Long-term personalization
- Memory poisoning
- Privacy and data protection

Sub-Agents
- Task delegation
- Isolated context windows
- Confused deputy attacks
- Trust boundaries

Agent Security
- Expanding attack surface
- Capability versus risk
- Secure agent design
- Defense-in-depth for AI systems

Learn more about Black Hills Information Security:
https://www.blackhillsinfosec.com/

Check out Antisyphon Training:
https://www.antisyphontraining.com/

#AISecurity #CyberSecurity #LLMSecurity #ArtificialIntelligence #AgenticAI #AIAgents #PromptInjection #InfoSec #BHIS #Antisyphon

  • (00:00) - Intro: Understanding Agentic AI Terminology
  • (01:28) - Prompts: Instructions and Prompt Injection
  • (07:00) - Skills: Reusable Knowledge and Supply Chain Risk
  • (11:55) - Tools: Permissions, Actions, and Least Privilege
  • (14:50) - Memory: Persistence and Memory Poisoning
  • (22:54) - Sub-Agents: Delegation and Trust Chains
  • (26:52) - Putting It All Together: Expanding Attack Surface
  • (27:58) - Final Takeaways

Click here to watch this episode on YouTube.

Creators & Guests

Brought to you by:

Black Hills Information Security 

https://www.blackhillsinfosec.com


☯️ Introducing BHIS Fusion Penetration Testing
https://www.blackhillsinfosec.com/fusion-penetration-testing/

Antisyphon Training

https://www.antisyphontraining.com/


Active Countermeasures

https://www.activecountermeasures.com


Wild West Hackin Fest

https://wildwesthackinfest.com

🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits
https://poweredbybhis.com

Click here to view the episode transcript.

links11