Privilege Escalation Through Tool Composition
組合工具達成越權
Re-evaluation
Risk Description
When to complete a task, the system independently combines available tools and obtains access capabilities never explicitly granted; due to unmitigated control gaps, each individual action falls within permissions, but the combined result far exceeds intent, and permission auditing conducted item by item fails to detect it, triggering compliance exposure and operational reputational costs.
Framework Mappings
OWASP Top 10 for LLMLLM06
NIST AI RMFGOVERN 3.2
ISO/IEC 23894§6.4
MAESTRO
ISO/IEC 5338運作與監控
MIT AI Risk RepositoryDomain 7
Risk Treatment & Implementation Guidance
Grant tools under least privilege and analyze the security of tool combinations, not items in isolation; Make high-risk combinations mutually exclusive or human-approved; Monitor agent trajectories rather than single actions, detecting capability acquisition beyond task intent