Skip to content
Search
paperJune 2026Unreviewed

Think Twice Before You Act: Protecting LLM Agents Against Tool Description Poisoning via Isolated Planning

Shanghao Shi, Xiao Wang, Chaoyu Zhang, Hao Li, Wenjing Lou, Thomas Hou, Yevgeniy Vorobeychik, Chongjie Zhang, Ning Zhang

Abstract

The integration of external tools has substantially expanded the capabilities of large language model (LLM) agents, but it also introduces new attack surfaces beyond prompt injection. In particular, cross-tool description poisoning can manipulate planner-visible tool metadata to steer an agent's trajectory, even if the poisoned tool itself is never chosen. To understand the effectiveness of existing defenses against this emerging threat, we first evaluate several prompt-injection defenses and fi

Categories

Framework mappings

OWASP Top 10 for LLM Applications
  • LLM01Prompt Injection
  • LLM04Data and Model Poisoning
MITRE ATLAS
  • AML.T0020Poison Training Data
  • AML.T0051LLM Prompt Injection

Suggested from the entry's categories.

Cite

@misc{shi2026think,
  title = {{Think Twice Before You Act: Protecting LLM Agents Against Tool Description Poisoning via Isolated Planning}},
  author = {Shanghao Shi and Xiao Wang and Chaoyu Zhang and Hao Li and Wenjing Lou and Thomas Hou and Yevgeniy Vorobeychik and Chongjie Zhang and Ning Zhang},
  year = {2026},
  month = jun,
  eprint = {2606.20922},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2606.20922}
}