Story · arXiv (via papers.cool)
ContextLeak: Exfiltrating LLM Agent Context via Malicious Tools (arXiv (via papers.cool))
paper · Story page

ContextLeak reinforcement-trains an attack model to craft a malicious tool's name and description so a victim agent both selects the tool and passes its private runtime context in as arguments. The disclosure step of tool-mediated exfiltration now has an automated attack.
In plain words
- Researchers developed an attack that tricks action-taking artificial intelligence into choosing a harmful tool and sharing private working information.
- Another artificial intelligence system learns to write the harmful tool's name and description so it appears useful.
- Once selected, the tool can receive the user's request, earlier actions, and list of available tools.
- Users face privacy risks because their private requests and action histories can become inputs to an attacker-controlled tool.
Appeared in
- Realistic prompts drop coding-agent scores, and tool filtering beats prompt rules
Sep 01, 2026 · in the sections
Subscribe
Get the brief in your inbox
Pick daily, weekly, or both. Nothing is gated either way: every issue is on the site and in the feeds.
- Weekdays at 8:45am IST, one lead story and 6 to 9 items.
- Sundays, an argued synthesis rather than a recap.
- One click to leave, and quiet days say so in the subject line.
