Banana Navy
Catalog FR
Lab · Threat modeling IA · Fiche détaillée

Tool, agent and workflow abuse

the model triggers an unauthorized external action by requesting it through a tool (tool hijacking, unauthorized write, workflow abuse, privilege escalation) or through an agent.

SheetF20
CategoryAI6-TB7 (tool / agent abuse)
Layers10 · Prompt Injection Filter, 14 · LLM Interpretation, 15 · Policy Engine, 16 · Workflow Execution
Systemvoicebot IA

deterministic per-tool backend authorization (allowlist, model-independent validation, token scoping, approval gates), individual review of every write and escalation tool.

The threat

the model triggers an unauthorized external action by requesting it through a tool (tool hijacking, unauthorized write, workflow abuse, privilege escalation) or through an agent.

Angle mortWhy classic frameworks miss it

the risk is not what you tell the system but what you enable it to do; an agent fits no classic exposure category.

MitigationProposed approach

deterministic per-tool backend authorization (allowlist, model-independent validation, token scoping, approval gates), individual review of every write and escalation tool.

The proposed control
an action requested through the model happens only if a deterministic backend authorizes it.

Expected evidence
demonstrate that an action requested through the model happens only if a deterministic backend authorizes it.

SourcesReferences and public research

MITRE ATLAS 2026.07AML.T0053 AI Agent Tool Invocation
OWASP GenAIOWASP GenAI LLM06:2025 Excessive Agency
Recherche publiquePublic research sources: MITRE ATLAS 2026.07 (verified technique mapping), OWASP GenAI (OWASP), and the public risk-voicebot (aivansoul/risk-voicebot) template defining the 20 checkpoints. No client registry data: generic sheet, no rating, no verdict.
couche 10 · Prompt Injection Filtercouche 14 · LLM Interpretationcouche 15 · Policy Enginecouche 16 · Workflow Execution

Explore the 20 security layers

MITRE ATLAS 2026.07 · OWASP GenAI · risk-voicebot