The Lethal Trifecta Blocking Agentic Commerce

David Levine says the lethal trifecta, private data plus untrusted content plus action, blocks agentic commerce until agent identity is verifiable.

S
StartupHub.ai Staff
3 min read
AI agent security concept illustrating private data, untrusted content and external actions
David Levine at AI Engineer on why agentic commerce needs verifiable identity· AI Engineer

The lethal trifecta is what stands between today's chatbots and real agentic commerce on the open internet, David Levine, who works on agent identity and governance, told the closing session at AI Engineer.

The Lethal Trifecta Blocking Agentic Commerce - AI Engineer
The Lethal Trifecta Blocking Agentic Commerce, from AI Engineer

His demo put an agent in a familiar spot: it had access to private files, bank logins and docs, then read untrusted web content and took actions like emailing or filing forms. An attacker doesn't need local access here. A poisoned webpage, email or job board post the agent will ingest is enough.

How a lethal trifecta attack actually works

An agent is naive by design. It treats the system prompt, user context and tool output as one flat instruction stream, so injected text can convince it the attacker is its principal.

Picture an intern who treats any note left on his desk as an order from the boss. If the note says forward the spreadsheet to an outside address, he does it, and the private data walks out.

Levine credited the term to programmer Simon Willison. The same failure has already hit Microsoft 365 Copilot, Slack AI, Notion AI and Amazon Q, any agent that combines the three legs.

Why this matters, and what's still broken

Enterprises have contained the risk by keeping agents siloed in Slack, Salesforce or Notion and stitching them with APIs and MCP servers. That breaks the trifecta, but it also kills context and composability.

Levine's fix is legal and cryptographic. He registered a Decentralized Unincorporated Nonprofit Association in West Virginia, org number 628407, and calls the agent-native version a Kiduna.

The design, originally from Andreessen Horowitz for DAOs, gives the collective legal standing to own assets, sign contracts and open bank accounts without a corporate shell or board. Agents get scoped JWT tokens rooted in the state filing and verifiable on chain, like DNS for organizations, so you can resolve whether you're talking to a real enterprise or an impersonator.

Governance uses decision markets, not votes. Members trade pass and fail tokens on policies, which Levine argued produces better outcomes than persuasion because token value aligns with the winning side.

The gap is adoption. A token standard only helps if sites, email gateways and frameworks enforce verification before acting, and no universal registry exists yet. Builders should default to removing one leg: isolate private data, block untrusted reads, or require human approval for external sends. When they must combine all three, narrowly scoped tokens with short time to live are the safer bet.

Levine opened early access at kaduna.club for a builder Kiduna with templates for sales, social and legal agents. If agents are to buy buildings and run companies, identity has to be as resolvable as a domain name. Today it isn't.

© 2026 StartupHub.ai. All rights reserved. You may not republish this article in full without a license. Search engines and AI research tools may crawl and summarize for reference. Bulk reproduction or model training requires a license. See our terms.
S

Written by

StartupHub.ai Staff

Editorial team

The staff writers of StartupHub.ai, ranging from investment analysts to avid AI tool users, early adopters and critical enthusiasts. Backgrounds span engineering, business and the arts. We hold every piece to rigorous standards of research and review.