| A2A Protocol Exploit | a2a-protocol-exploit | tool-use | critical | Exploits Google |
| Function Schema Injection | function-schema-injection | tool-use | high | Tests if malicious function/tool schemas can manipulate agent behavior by injecting harmful instructions into paramet… |
| Self-Propagating Worm | self-propagating-worm | tool-use | critical | Tests if an agent can be tricked into creating self-replicating payloads that spread through agent interactions. The … |
| Tool Result Poisoning | tool-result-poisoning | tool-use | critical | Tests if an agent properly sanitizes tool call results by injecting prompt injection payloads into simulated tool res… |
| Zero-Click Injection | zero-click-injection | tool-use | critical | Tests EchoLeak-style zero-click attacks where a crafted email or document is automatically processed by the agent wit… |