SIGNAL//DESK
AI securitysrc: MITRE ATLAS

Publish Poisoned AI Agent Tool

Bad actors can create fake or tampered-with software tools for AI assistants and share them online. When a user installs one of these 'poisoned' tools, it can secretly contain hidden instructions that trick the AI into doing things it shouldn't, like leaking private data or performing unauthorized actions.

Adversaries distribute compromised AI agent tools via public repositories, package managers, or remote server endpoints. These tools are embedded with malicious LLM prompt injections that execute when the agent interacts with the tool, enabling unauthorized control, data exfiltration, or other downstream security impacts.

The publication of poisoned AI agent tools involves the deployment of malicious software artifacts—such as compromised plugins, MCP servers, or library packages—to public registries or version control systems. These artifacts incorporate embedded LLM prompt injection vectors (AML.T0051) designed to manipulate the agent's execution context, effectively weaponizing the agent's tool-use capabilities to achieve adversarial objectives.


← all terms