Skip to content
ATR-2026-00099lowExcessive Autonomyexperimental

High-Risk Tool Invocation Without Human Confirmation

Detects when an AI agent invokes high-risk tools (financial, destructive, communication, or permission-altering) without evidence of human confirmation in the current interaction turn. This is a defense-in-depth rule that complements specific attack detection -- even if no injection is detected, certain tool categories should ALWAYS require human-in-the-loop. High-risk tool categories: 1. Financial: payments, transfers, purchases, subscriptions 2. Destructive: file deletion, database drops, account deletion 3. Communication: sending messages, emails, posts on behalf of user 4. Permission: granting access, changing roles, modifying auth 5. System: process execution, system commands, network operations This rule enforces the principle of least privilege for agent tool access. Any tool matching these categories should trigger an "ask" verdict regardless of confidence score.

嚴重度
low
類別
Excessive Autonomy
掃描目標
mcp
作者
ATR Community

建議回應

block toolalert

參考資料

OWASP Agentic
ASI08:2026 - Excessive AutonomyASI09:2026 - Inadequate Access ControlsASI10:2026 - Insufficient Human Oversight
OWASP LLM
LLM06:2025 - Excessive Agency
MITRE ATLAS
AML.T0053 - LLM Plugin Compromise