๐Ÿ›ก๏ธ NAIL Institute โ€” AVE Database

โ† Back to Database

Confused Deputy Attack

๐Ÿ”ด CRITICAL tool proven AVE-2025-0026

ยท aka: Tool Trust Exploitation, Tool Description Poisoning

Summary

LLMs blindly trust their own tool descriptions. When a tool description is poisoned to request PII or secrets, the model complies. 100% exploitation rate on Claude and Gemini.

Blast Radius

Full PII/API key exfiltration. Cross-model systemic vulnerability.

Prerequisites

Agent with tool-calling capability and dynamic tool registry.

Environment

  • Frameworks: LangGraph
  • Models tested: [Available in NAIL SDK]
  • Multi-agent: No
  • Tools required: Yes
  • Memory required: No

Related