Agent Hijacking
Attacker влияе на autonomous/semi-autonomous agent така, че задачата му, memory или tool selection се пренасочва.
Какво е
Attacker влияе на autonomous/semi-autonomous agent така, че задачата му, memory или tool selection се пренасочва.
Как работи
Indirect prompt injection, malicious tool response или poisoned memory/context въвежда attacker instructions, които agent следва през няколко стъпки.
Как да се предотврати
Trust labels за inputs, immutable policy constraints, tool allow-list, isolated memory, provenance, step-level authorization и human approval за high-impact branches.
Най-ефективни защити
Подредени по приоритет — P0 е мястото, от което се започва.