AI Risk Atlas Prototype/DemoUnofficial independent experiment. Not an official xAI product. Scores can be wrong.

Back to watch register
15Prompt injectionBelow the top 20

Injection through tool descriptions

CapabilityAffordanceImpact domainCap-adjacent

Statement (NASA form)

Given that agents trust tool schemas and descriptions as if they were written by the vendor, there is a possibility of a malicious or compromised tool rewriting the agent’s policy in its docstring resulting in the agent changing jobs because a JSON field told it to.

Likelihood
3Probable
Consequence
4Critical
Urgency
3Priority

The schema is also a prompt. Treat it like one.

Composite 15 = 3×4 + 3

Applicable mitigations

Related on the map