Research · curated 6 Sep 2026
Pwning Agentic AI Part I: Your AI Agent Is Already Compromised | TrendAI (US)
First reported trendaisecurity.com
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
Return-to-tool exploits weaponize an AI agent's own legitimate tool privileges via hidden instructions in benign-looking text, letting attackers exfiltrate data without triggering alerts or violating policy, which defeats traditional perimeter controls around widely deployed MCP agents.
TrendAI Research describes 'return-to-tool' (RTT), a subclass of indirect prompt injection in which embedded instructions in untrusted input cause a database-connected AI agent to invoke its own authorized tools against the principal it serves, exfiltrating sensitive data such as authentication tokens and customer records. The write-up notes a vulnerable PostgreSQL MCP Docker image pulled over 100,000 times and walks through production scenarios where existing controls (sandboxing, WAFs, egress restrictions) fail to detect the abuse.