On the Security of Tool-Invocation Prompts for LLM-Based Agentic Systems: An Empirical Risk Assessment

  • 2025-09-19 17:17:58
  • Yuchong Xie, Mingyu Luo, Zesen Liu, Zhixiang Zhang, Kaikai Zhang, Yu Liu, Zongjie Li, Ping Chen, Shuai Wang, Dongdong She
  • 0

Abstract

LLM-based agentic systems leverage large language models to handle userqueries, make decisions, and execute external tools for complex tasks acrossdomains like chatbots, customer service, and software engineering. A criticalcomponent of these systems is the Tool Invocation Prompt (TIP), which definestool interaction protocols and guides LLMs to ensure the security andcorrectness of tool usage. Despite its importance, TIP security has beenlargely overlooked. This work investigates TIP-related security risks,revealing that major LLM-based systems like Cursor, Claude Code, and others arevulnerable to attacks such as remote code execution (RCE) and denial of service(DoS). Through a systematic TIP exploitation workflow (TEW), we demonstrateexternal tool behavior hijacking via manipulated tool invocations. We alsopropose defense mechanisms to enhance TIP security in LLM-based agenticsystems.

 

Quick Read (beta)

loading the full paper ...