Tool shadowing
A malicious server describing its tool so persuasively that the model prefers it to the legitimate one.
When several servers are connected at once, the model chooses between tools by reading their descriptions. A server can write a description engineered to win that comparison, and it does not have to be dishonest about anything else to do it.
The effect is that work you expected to go to a trusted integration silently goes somewhere else, with all the arguments attached. Nothing was exploited; a selection was influenced.
It is the attack that arrives with more connected servers rather than with worse ones, so it gets more likely exactly as an agent setup gets more useful.
Assuming this needs the malicious server to be doing anything else wrong. Shadowing works perfectly well from a server that is otherwise clean.
Related terms
See Tool shadowing on a real listing
Every term here shows up in the catalogue next to a real result, with the findings published and the limits stated. Free to browse, no account needed.
Open the catalogue