Tool ShadowTier 2critical
Tool Shadow: Invisible API Call
Hidden tool invocations and shadow function calls
Invisible API calls are background requests that the agent makes without surfacing them to the user, potentially leaking data or triggering actions covertly.
Attack Details
- Attack ID
- APWN-TS-002
- HMA Check
- TOOL-004
- Delivery Methods
- html-comment, invisible-span
- CWE
- CWE-441
- OASB Control
- 12.2
- Severity
- critical
Remediation
If your AI agent is vulnerable to this attack, scan and fix with:
npx hackmyagent secure --check TOOL-004