Definition · foundations
tool poisoning
tool poisoning is an attack that alters a tool, its description, or its output so an agent is misled or compromised. You can spot tool poisoning in practice when the record shows what the system observes, what choice it makes, and what changes next, without asking the reader to guess or trust a slogan.
157 definitions656 sourced recordsNamed source: ACL Anthology
Why does tool poisoning matter?
A poisoned tool can lie through its description or output. The agent may then grant data or trust to an attacker. For tool poisoning, start with three checks: What can the system observe? What choice can it make? What changes after it acts? The answers should point to visible evidence, not a promise.
What does tool poisoning look like?
A fake search tool asks for a secret key before it returns any result. This example makes tool poisoning visible by naming the actor, the action, and the result in practice. It is an illustration for readers, not a claim that every product behaves this way.
What is tool poisoning easy to confuse with?
Tool poisoning corrupts a tool or its metadata. Prompt injection hides bad commands in input content. The closest entries here are tool invocation, tool registry, tool schema. Compare their definitions with tool poisoning before using the names as if they mean the same thing. That comparison keeps tool poisoning separate from nearby ideas without pretending the boundary is always perfect.
How certain is this definition?
This definition is provisional. ACL Anthology supports the version you see today, but a better or more direct source may change it. Open the cited page and check its date before you use this entry to choose a product, write a policy, set a safety control, or design a system.
Who introduced the term tool poisoning?
We have not verified who first introduced tool poisoning. The source supports a useful definition, but it may not be the earliest use. Until a dated primary record settles the question, we leave the origin open. A popular article or product page is not enough to name the person who coined a term.
What should you understand before tool poisoning?
Read artificial intelligence (AI) first when tool poisoning depends on a more basic idea or mechanism. The link gives you a useful route through the glossary. It does not mean every author teaches the subject in this order, so follow the source when the sequence matters.
What should this term help you answer?
Use tool poisoning to ask what an agent can observe, decide, change, remember, or hand off. The questions below turn the definition into a practical check. They are prompts for your own work, not claims made by the source, so change them to fit the system you are examining.
- What can the system observe?
- What choice can it make?
- What changes after it acts?
Which source supports this definition of tool poisoning?
ACL Anthology supports this working definition of tool poisoning. We checked the link on 2026-07-12. Open the original record for its context, methods, limits, and publication details. The short explanation here is a guide to tool poisoning; the linked source remains the evidence to inspect when the wording or boundary matters.
source foundtool poisoningChecked 2026-07-12→