Injection through tool descriptions
Statement (NASA form)
Given that agents trust tool schemas and descriptions as if they were written by the vendor, there is a possibility of a malicious or compromised tool rewriting the agent’s policy in its docstring resulting in the agent changing jobs because a JSON field told it to.
The schema is also a prompt. Treat it like one.
Composite 15 = 3×4 + 3
Applicable mitigations
Controls · Dual control on irreversible actions · Strict isolation of untrusted content from instructions · Hidden-text and steganographic scanning of filings · Short-lived, narrowly scoped tokens for every tool call · Mandatory secret scanning before a skill can be listed · No shared tool state across agent sessions