ContextLeak: Malicious tools can exfiltrate 92% of Agent context

rohanpaul_ai · x · 2026-09-01

A paper titled "ContextLeak" reveals a new attack vector where malicious agent tools can exfiltrate sensitive runtime data (e.g., user prompts, conversation history) simply by having their names and descriptions crafted to trick the LLM agent into including them as tool arguments.

Attack Mechanics & Effectiveness:

Related event: ContextLeak Attack Steals AI Agent Context via Malicious Tools(2 posts)→

Original post →

More from Safety

Safety channel →