ยท aka: Secret Exfiltration, API Key Exposure
Agents inadvertently expose API keys, tokens, or credentials in their responses when tool outputs contain sensitive data. The agent treats tool output as displayable content.
API keys, database credentials, or session tokens exposed. Lateral movement possible.
Agent with access to tools that return credential-bearing responses.