SOK: Bridging Research and Practice in LLM Agent Security

SEI Report
This systematic review discusses academic surveys, grey literature sources, and real-world case studies on securing LLM agents.
Publisher

Software Engineering Institute

DOI (Digital Object Identifier)
10.1184/R1/30610928

Abstract

Large Language Model agents are rapidly transitioning from research prototypes to deployed systems, raising new and urgent security challenges. Unlike static chatbots, LLM agents interact with external tools, data, and services, creating pathways to real-world harm even during early stages of development. Existing guidance on securing agents is fragmented, creating obstacles for developers and organizations looking to build secure systems. To clarify the security landscape, we conduct a systematic review covering academic surveys, grey literature sources, and real-world case studies. We then (i) categorize the known threats to LLM agents and analyze key attack surfaces, (ii) construct a taxonomy of actionable security best practices encompassing the full LLM agent development lifecycle, highlighting gaps in the security landscape, and (iii) evaluate the adoption of these recommendations in practice. Together, these contributions establish a framework for developing comprehensive risk-mitigation strategies. Our synthesis promotes standardization, surfaces gaps in current practice, and establishes a foundation for future work toward secure LLM agents.

Cite This SEI Report

Grimes, K., Lawler, J., Garrett, R., Mathew, E., Christiani, M., Kingsley, S., Wu, Z., & VanHoudnos, N. (2025, November 20). SOK: Bridging Research and Practice in LLM Agent Security. Retrieved September 12, 2026, from https://doi.org/10.1184/R1/30610928.

@techreport{grimes_2025,
author={Grimes, Keltin and Lawler, Julie and Garrett, Robert C. and Mathew, Emil and Christiani, Marco and Kingsley, Sara and Wu, Zhiwei Steven and VanHoudnos, Nathan},
title={SOK: Bridging Research and Practice in LLM Agent Security},
month={Nov},
year={2025},
institution={Software Engineering Institute, Carnegie Mellon University},
doi={10.1184/R1/30610928},
url={https://doi.org/10.1184/R1/30610928},
note={Accessed: 2026-Sep-12}
}

Grimes, Keltin, Julie Lawler, Robert C. Garrett, Emil Mathew, Marco Christiani, Sara Kingsley, Zhiwei Steven Wu, and Nathan VanHoudnos. "SOK: Bridging Research and Practice in LLM Agent Security." Software Engineering Institute, Carnegie Mellon University. Software Engineering Institute, November 20, 2025. https://doi.org/10.1184/R1/30610928.

K. Grimes, J. Lawler, R. Garrett, E. Mathew, M. Christiani, S. Kingsley, Z. Wu, and N. VanHoudnos, "SOK: Bridging Research and Practice in LLM Agent Security," Software Engineering Institute, Carnegie Mellon University. Software Engineering Institute, 20-Nov-2025 [Online]. Available: https://doi.org/10.1184/R1/30610928. [Accessed: 12-Sep-2026].

Grimes, Keltin, Julie Lawler, Robert C. Garrett, Emil Mathew, Marco Christiani, Sara Kingsley, Zhiwei Steven Wu, and Nathan VanHoudnos. "SOK: Bridging Research and Practice in LLM Agent Security." Software Engineering Institute, Carnegie Mellon University, Software Engineering Institute, 20 Nov. 2025. https://doi.org/10.1184/R1/30610928. Accessed 12 Sep. 2026.

Grimes, Keltin; Lawler, Julie; Garrett, Robert C.; Mathew, Emil; Christiani, Marco; Kingsley, Sara; Wu, Zhiwei Steven; & VanHoudnos, Nathan. SOK: Bridging Research and Practice in LLM Agent Security. Software Engineering Institute. 2025. DOI: 10.1184/R1/30610928. https://doi.org/10.1184/R1/30610928