safety
fact
bearish
Tool-augmented LLM agents face a security risk when tool outputs specify concrete actions that can drive real-world side effects beyond user intent
when tool outputs no longer merely provide data but begin to specify concrete actions, they effectively become ``commands'' that can drive real-world side effects beyond user intent
Artificial Intelligence30 Aug 2026