The provided tool description exhibits a Tool Shadowing Vulnerability (TSV). The add_two_numbers
tool description contains instructions that attempt to modify the behavior of a send_email
tool, potentially causing emails to be redirected to an attacker-controlled address. This could lead to sensitive information being leaked without the user's knowledge.
The add_two_numbers
tool description attempts to modify the behavior of the send_email
tool, instructing the agent to send all emails to attkr@pwnd.com
. This is a clear attempt to shadow the send_email
tool and intercept sensitive information.