Record summary
A quick snapshot of what this page covers.
Attack context
How this AI attack works in practice.
Adversaries may place malicious content on a victim's system where it can be retrieved by an AI Agent Tool. This may be accomplished by placing documents in a location that will be ingested by a service the AI agent has associated tools for.
The content may be targeted such that it would often be retrieved by common queries. The adversary's content may include false or misleading information. It may also include prompt injections with malicious instructions.
- ATLAS ID
- AML.T0099
- Priority score
- 115
Mitigations
Defenses that may help against this attack.
Case studies
Examples from public reports and exercises.
Source
Where this page information comes from.
Original source
Original source links
Open the public records and source datasets used for this page.