AI Security Ops

← AI Security Ops31 Jul · 29 min

Agentic Terminology | Episode 64

Agentic Terminology | Episode 6431 Jul29 min

In this episode of BHIS Presents: AI Security Ops, the team tackles one of the biggest sources of confusion in modern AI:

What’s the difference between prompts, skills, tools, memory, and sub-agents?

These terms are everywhere in discussions about agentic AI. They’re often used interchangeably—but they describe very different capabilities. More importantly, each one introduces its own unique security risks.

If you’re building, deploying, or securing AI agents, understanding this vocabulary isn’t just helpful. It’s essential.

Because every new capability an agent gains is also a new attack surface.

We break down each core building block of agentic systems, explain what it actually does, and discuss how attackers can abuse it—from prompt injection and memory poisoning to supply-chain attacks and excessive tool permissions.

We dig into:

- The difference between prompts, skills, tools, memory, and sub-agents

- Why prompts define behavior but don’t create lasting capability

- How skills package reusable expertise without granting new permissions

- Why tools are what allow AI agents to take real-world actions

- The security risks of giving agents excessive privileges