Research · curated 6 Sep 2026

Pwning Agentic AI Part I: Your AI Agent Is Already Compromised | TrendAI (US)

Coverage timeline

6 Sep 2026trendaisecurity.com

Single-source research — first reported, latest, and curated coincide.

Why it matters

Return-to-tool exploits weaponize an AI agent's own legitimate tool privileges via hidden instructions in benign-looking text, letting attackers exfiltrate data without triggering alerts or violating policy, which defeats traditional perimeter controls around widely deployed MCP agents.

TrendAI Research describes 'return-to-tool' (RTT), a subclass of indirect prompt injection in which embedded instructions in untrusted input cause a database-connected AI agent to invoke its own authorized tools against the principal it serves, exfiltrating sensitive data such as authentication tokens and customer records. The write-up notes a vulnerable PostgreSQL MCP Docker image pulled over 100,000 times and walks through production scenarios where existing controls (sandboxing, WAFs, egress restrictions) fail to detect the abuse.