Exploiting Tool and Function Calling in LLM Agents
blog.sentry.security | 博客 | #ai-security | #prompt-injection | #ai-agents | #llm | #owasp | #tool-calling
摘要
深入剖析 LLM 智能体中工具与函数调用的攻击面:暴露的 messages[]、特权角色及未正确转义的控制 token 可被利用来操纵智能体行为,对应 OWASP LLM06「过度代理」风险。
- 发布时间
- 收录时间
Skip to content