AML.T0099: AI Agent Tool Data Poisoning
Adversaries may place malicious content on a victim's system where it can be retrieved by an AI Agent Tool. This may be accomplished by placing documents in a location that will be ingested by a service the AI agent has associated tools for.
The content may be targeted such that it would often be retrieved by common queries. The adversary's content may include false or misleading information. It may also include prompt injections with malicious instructions.
Standards mapping
Where this fits in a TurboPentest engagement
This weakness is not covered by the automated black-box pentest. IntegSec pentesters cover it in a manual engagement.
Frequently asked questions
What is AML.T0099 AI Agent Tool Data Poisoning?
Adversaries may place malicious content on a victim's system where it can be retrieved by an AI Agent Tool. This may be accomplished by placing documents in a location that will be ingested by a service the AI agent has associated tools for. The content may be targeted such that it would often be retrieved by common queries. The adversary's content may include false or misleading information. It may also include prompt injections with malicious instructions.
Which tactics does AML.T0099 belong to?
AML.T0099 maps to the Persistence tactic.
Does TurboPentest test for AI Agent Tool Data Poisoning?
This weakness is not covered by the automated black-box pentest. IntegSec pentesters cover it in a manual engagement.
Related MITRE ATLAS techniques
- Persistence, AI Attack StagingAML.T0018: Manipulate AI Model
- Resource Development, PersistenceAML.T0020: Poison Training Data
- PersistenceAML.T0061: LLM Prompt Self-Replication
- PersistenceAML.T0070: RAG Poisoning
- PersistenceAML.T0080: AI Agent Context Poisoning
- Persistence, Defense EvasionAML.T0081: Modify AI Agent Configuration
About this reference
These security references are maintained by IntegSec, an offensive-security firm whose team holds CISSP, OSCP, and OSCE certifications and has run thousands of penetration tests. Content is kept current as tools, standards, and attack techniques evolve.
Find these issues before an attacker does
TurboPentest runs an agentic AI pentest against your target and reports findings with proof, from $99 per target.
Start a pentest