Poisoning an AI tool exposes a major flaw in enterprise agent security

AI agents select tools from shared registries according to natural language descriptions. But no one confirms whether these descriptions are true or not. I discovered this loophole while submitting issue 141 in CoSAI secure-ai-tools repository. I assumed this would be…










