Tampering with a tool an agent uses, through its model-visible definition (description, schema, metadata) or its behaviour, so the agent acts on false premises. OWASP files manipulation of a legitimate tool's interface under ASI02 and a tool compromised at the source under ASI04 1; MITRE ATLAS lists AI Agent Tool Poisoning (AML.T0110) 2.
- Developed in
- ch. 23, Admitting an MCP server
- Chapters
- ch. 23, AI Agents
- Contrast with
- Prompt injection
- Source
- 2 numbered references, listed below
Where it is used
One chapter of the Body of Knowledge uses the term. Each link opens the first section that does.
- 23 · AI Agents Tool and MCP server permissions 3 mentions
Related terms
Sources
- [1] Top 10 for Agentic Applications 2026 (ASI01 Agent Goal Hijack; ASI02 Tool Misuse and Exploitation; ASI03 Identity and Privilege Abuse; ASI04 Agentic Supply Chain Vulnerabilities; ASI05 Unexpected Code Execution (RCE); ASI06 Memory & Context Poisoning; ASI07 Insecure Inter-Agent Communication; ASI08 Cascading Failures; ASI09 Human-Agent Trust Exploitation; ASI10 Rogue Agents; Least-Agency; per-tool least-privilege profiles; tool poisoning of a legitimate tool's interface under ASI02, a tool compromised at the source under ASI04). OWASP GenAI Security Project. 2025-12-09. https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/ (verified: primary)
- [2] MITRE ATLAS data, release v2026.09 (AML.T0080 AI Agent Context Poisoning, .000 Memory; AML.T0110 AI Agent Tool Poisoning). MITRE. 2026-09-15. https://github.com/mitre-atlas/atlas-data/releases/tag/v2026.09 (verified: primary)
Definitions of legal terms paraphrase the cited text, which governs. Dated statements are as of .