Attack  ·  Glossary

Malicious API spec (AI agent code-generation injection)

An attack where a crafted software interface description (such as a Swagger/OpenAPI file) is fed into a tool that auto-generates AI plugin or agent code. Because the generator trusts the spec's contents, it can inject operating-system commands or malicious code paths into the code it produces, and can even pull attacker-controlled configuration into the plugin manifest. Developers routinely pull such specs from public registries, vendor exports, or pull requests.
This is a supply-chain-style foothold: one poisoned API document can hand an attacker code execution inside an AI coding agent, so any external API spec should be treated as untrusted input.
OWASP GenAI Security Project
Track this in the live feed See how this plays out in real AI security and governance developments.
Open the feed →