S0143RS5-T17-S0143-Z · Full risk code

Privilege Escalation Through Tool Composition

組合工具達成越權

Re-evaluation
Risk Description

When to complete a task, the system independently combines available tools and obtains access capabilities never explicitly granted; due to unmitigated control gaps, each individual action falls within permissions, but the combined result far exceeds intent, and permission auditing conducted item by item fails to detect it, triggering compliance exposure and operational reputational costs.

Framework Mappings

OWASP Top 10 for LLMLLM06
NIST AI RMFGOVERN 3.2
ISO/IEC 23894§6.4
MAESTRO
ISO/IEC 5338運作與監控
MIT AI Risk RepositoryDomain 7

Risk Treatment & Implementation Guidance

Grant tools under least privilege and analyze the security of tool combinations, not items in isolation; Make high-risk combinations mutually exclusive or human-approved; Monitor agent trajectories rather than single actions, detecting capability acquisition beyond task intent