Slide 28 of 28
Part 4 — PreventionSlide 28
Module Complete
You finished AG02. Here's what you now understand:
What Tool Misuse and Exploitation is — and why "everything was authorized" is what makes it dangerous
The two types: Over-Privileged Tools (Type 1) and Tool Chaining/Injection (Type 2)
Real documented attacks: AgentFlayer, Amazon Q DNS exfil, MCP descriptor poisoning, EDR bypass via tool chain
Why MCP expanded the ASI02 attack surface and what tool descriptor poisoning looks like
The root cause: authorization and intent are separated in agentic systems
7 mitigations and which ones stop which attacks — with the matrix to prove it
← Review AG02 Next Module → AG03