S-06Tool Poisoning

/security/tool-poisoning

A tool’s own manifest or output carries instructions — and models trust their tools more than the web.

Key insight

Tool descriptions are code you execute in the model’s head. Pin them, diff them, review them like dependencies — because that’s what they are.

Failure mode

Auto-updating tool manifests: the version you reviewed is not the version in context.

Further reading

Elsewhere in the atlas