MAESTRO

OWASP AIVSS Core Security Risks

Interactive Learning Module

🎓 Free for Everyone: Take all training courses and exams at no cost

🏆 Premium Members: Pass 7+ exams (70%+ score) to unlock your professional certificate

Learning Progress0 / 10

📝 Pass 7+ exams with 70%+ scores to unlock certificate (0/7 passed)

Core Risks
Core-1
Agentic AI Tool Misuse

Agent's interaction with tools results in aberrant operational outcomes

Overview

Agentic AI Tool Misuse occurs when an agent's interaction with externalized functionalities, including tools, capabilities, or resources, results in aberrant or detrimental operational outcomes. This can stem from compromised integrity of toolchain integrations, deficiencies in the agent's inferential capabilities, malicious injection of tool specifications, or lack of cryptographic provenance.

Key Risks
Example Attack Scenarios

Malicious Code Execution: LLM agent manipulated into executing arbitrary code via interpreter tool

Tool Squatting: Fraudulent storage service intercepts and exfiltrates sensitive data

DoS via Tool Loop: Infinite invocation of resource-intensive tools exhausting system resources

MCP Server Backdoor: Rogue Model Context Protocol server injecting persistent backdoors

Metadata Manipulation: Hidden instructions in tool metadata manipulating agent actions

Rogue Trading Agent: Financial agent executing unauthorized trades without effective kill switch

Test Your Understanding