|
|
|
|
|
by jstanley
434 days ago
|
|
> None of these involve crossing a privilege boundary, they just found a weird way to do something they could already do It's slightly more subtle than that. The tool poisoning attack allows the provider of one tool to cause the AI to use another tool. So if you give the AI some random weather tool from some random company, and you also give the AI access to your SSH key, you're not just giving the AI your SSH key, you're also allowing the random company to trick the AI into telling them your SSH key. So, yes, you gave the AI access to your key, but maybe you didn't realise that you also gave the random weather company access to your key. |
|