ยท aka: Tool Trust Exploitation, Tool Description Poisoning
LLMs blindly trust their own tool descriptions. When a tool description is poisoned to request PII or secrets, the model complies. 100% exploitation rate on Claude and Gemini.
Full PII/API key exfiltration. Cross-model systemic vulnerability.
Agent with tool-calling capability and dynamic tool registry.