These are two ways attackers abuse an AI agent rather than hacking its infrastructure directly. A malicious API spec poisons the specifications an agent uses to generate code, quietly injecting unwanted behavior, while covert exfiltration tricks the agent's legitimate tools into smuggling data out under the guise of normal work. Both turn the agent into an unwitting insider threat.
Glossary topic
Agentic AI attack techniques
Terms in this topic
Track this in the live feed
See how this plays out in real AI security and governance developments.
Open the feed →