ATR-2026-00096criticalTool Poisoningdraft
Skill Registry Poisoning and Compromised Tool Distribution
Detects supply chain attacks that target skill/tool registries and distribution channels. Attackers compromise legitimate tool packages, inject backdoors into published skills, or create typosquatting tool names to distribute poisoned tools that execute malicious actions when installed or invoked by agents.
嚴重度
critical
類別
Tool Poisoning
掃描目標
mcp
作者
ATR Community (MiroFish Predicted)
建議回應
block inputquarantine sessionalertescalatekill agent
參考資料
MITRE ATLAS
AML.T0056