MITRE ATLAS 2026.09 / technique reference
AML.T0053
AI Agent Tool Invocation
MITRE source definition
Adversaries may use their access to an AI agent to invoke tools the agent has access to. LLMs are often connected to other services or resources via tools to increase their capabilities. Tools may include integrations with other applications, access to public or private data sources, and the ability to execute code.
This may allow adversaries to execute API calls to integrated applications or services, providing the adversary with increased privileges on the system. Adversaries may take advantage of connected data sources to retrieve sensitive information. They may also use an LLM integrated with a command or script interpreter to execute arbitrary instructions.
AI agents may also invoke applications indirectly through operating-system mechanisms such as deep links, app-intent URIs, universal links, or redirect chains. This can cause an installed application to open or perform an application-specific action even when that application was not selected as a direct agent tool, potentially avoiding normal user-confirmation workflows.
AI agents may be configured to have access to tools that are not directly accessible by users. Adversaries may abuse this to gain access to tools they otherwise wouldn't be able to use.
Source modified 2026-07-31. Reproduced from the pinned ATLAS release; inline technique links resolve to local reference pages.
Parent, sub-techniques and ATT&CK references
No explicit relationship in this pinned source.
Source-backed defensive context
MITRE mitigations
- AML.M0020 Generative AI Guardrails
- AML.M0021 Generative AI Guidelines
- AML.M0022 Generative AI Model Alignment
- AML.M0024 AI Telemetry Logging
- AML.M0026 Privileged AI Agent Permissions Configuration
- AML.M0027 Single-User AI Agent Permissions Configuration
- AML.M0028 AI Agent Tools Permissions Configuration
- AML.M0029 Human In-the-Loop for AI Agent Actions
- AML.M0030 Restrict AI Agent Tool Invocation on Untrusted Data
- AML.M0032 Segmentation of AI Agent Components
- AML.M0033 Input and Output Validation for AI Agent Components
- AML.M0035 AI Red Team
MITRE case studies
- AML.CS0016 Achieving Code Execution in MathGPT via Prompt Injection · Exercise
- AML.CS0021 ChatGPT Conversation Exfiltration · Exercise
- AML.CS0024 Morris II Worm: RAG-Based Attack · Exercise
- AML.CS0026 Financial Transaction Hijacking with M365 Copilot as an Insider · Exercise
- AML.CS0038 Planting Instructions for Delayed Automatic AI Agent Tool Invocation · Exercise
- AML.CS0039 Living Off AI: Prompt Injection via Jira Service Management · Exercise
- AML.CS0045 Data Exfiltration via an MCP Server used by Cursor · Exercise
- AML.CS0046 Data Destruction via Indirect Prompt Injection Targeting Claude Computer-Use · Exercise
- AML.CS0048 Exposed ClawdBot Control Interfaces Leads to Credential Access and Execution · Exercise
- AML.CS0049 Supply Chain Compromise via Poisoned ClawdBot Skill · Exercise
- AML.CS0051 OpenClaw Command & Control via Prompt Injection · Exercise
- AML.CS0052 LLMSmith: RCE Vulnerabilities in LLM-Integrated Applications · Exercise
- AML.CS0054 Data Exfiltration via Remote Poisoned MCP Tool · Exercise
- AML.CS0055 AI ClickFix: Hijacking Computer-Use Agents Using ClickFix · Exercise
- AML.CS0062 RCE Vulnerability in Semantic Kernel Search Plugin · Exercise
- AML.CS0063 Prompt-Based Attacks Against Gemini via Calendar Invitations · Exercise
- AML.CS0064 Poisoned GGUF Templates: Inference-Time Supply Chain Attack · Exercise
- AML.CS0066 ZombieAgent: Data Exfiltration Attack on ChatGPT · Exercise
- AML.CS0067 Claude Code GitHub Action Secret Exposure · Exercise
These are explicit source relationships, not independently reproduced incidents or validated detection coverage.
Simulation and telemetry boundary
This is a technique reference page, not a runnable simulation. No ATLAS-specific telemetry mapping, local attack execution or detector validation is asserted. MITRE maturity describes its source evidence, not a 1200km lab result.
For broader context—not technique-specific control mappings—see AI Security, AI Security Course, and detection-validation methodology.
Provenance and attribution
Immutable MITRE ATLAS source · Import provenance · Attribution and transformation notice · Apache License 2.0
Copyright 2021-2026 MITRE. Source text and explicit relationships are retained; navigation, formatting and local links are provided by 1200km.
No explicit relationship in this pinned source.