Skip to content

Agents & Agentic AI

Tool poisoning

Hiding misleading instructions in information about or returned by a tool to steer an AI improperly.

Example

An agent encounters misleading instructions embedded in a tool response.

Why people use it

It highlights misleading material that reaches an agent through a tool connection.

What you'll hear

“The tool description contains instructions we didn't authorize.”

What this means for you

Separate tool results from authority to change the agent's instructions.

Can you control it?

Sometimes

Sometimes. Your choices depend on the tool and your access. The settings available to an everyday user may differ from those available to the people running it.

Common questions

Does trusting a tool's basic function mean every returned instruction is trustworthy?
No. Tool data can contain untrusted or adversarial content.
Can a useful tool still expose unsafe content?
Yes. A tool can perform its basic job while returning material that tries to mislead the agent.
Does poisoning require changing the user's request?
No. The unwanted directions can arrive through material the agent reads during the task.

Related terms

Still have questions?

Up to 500 characters.

Ask LATHIC about AI. Relevant glossary entries may be included.

Your question, the glossary entries it matches, and a rotating pseudonymous identifier go to Microsoft Azure’s OpenAI service through Vercel AI Gateway to generate an answer. Zero retention and no training are required of the provider, and LATHIC does not save your question or answer. Privacy Notice