Agents & Agentic AI
Tool poisoning
Hiding misleading instructions in information about or returned by a tool to steer an AI improperly.
Example
An agent encounters misleading instructions embedded in a tool response.
Why people use it
It highlights misleading material that reaches an agent through a tool connection.
What you'll hear
“The tool description contains instructions we didn't authorize.”
What this means for you
Separate tool results from authority to change the agent's instructions.
Can you control it?
Sometimes
Sometimes. Your choices depend on the tool and your access. The settings available to an everyday user may differ from those available to the people running it.
Common questions
- Does trusting a tool's basic function mean every returned instruction is trustworthy?
- No. Tool data can contain untrusted or adversarial content.
- Can a useful tool still expose unsafe content?
- Yes. A tool can perform its basic job while returning material that tries to mislead the agent.
- Does poisoning require changing the user's request?
- No. The unwanted directions can arrive through material the agent reads during the task.