Tool Shadow:T1T2T3
Tool ShadowTier 2critical

Tool Shadow: Invisible API Call

Hidden tool invocations and shadow function calls

Invisible API calls are background requests that the agent makes without surfacing them to the user, potentially leaking data or triggering actions covertly.

Attack Details

Attack ID
APWN-TS-002
HMA Check
TOOL-004
Delivery Methods
html-comment, invisible-span
CWE
CWE-441
OASB Control
12.2
Severity
critical

Remediation

If your AI agent is vulnerable to this attack, scan and fix with:

npx hackmyagent secure --check TOOL-004