CustomLabs
Security & governance

Tool Poisoning

Tool poisoning hides an instruction in a tool's description that the model reads as legitimate.

It works because nothing marks a description field as untrusted data rather than a directive.

A server never called maliciously can still poison the session the moment its tools are listed.

Treating every description as untrusted unless the server is vetted is the standing defense.

← Back to the full glossary

Source: https://customlabs.io/glossary/tool-poisoning/

navigate select esc close