You finished AG02. Here's what you now understand:
✓What Tool Misuse and Exploitation is — and why "everything was authorized" is what makes it dangerous
✓The two types: Over-Privileged Tools (Type 1) and Tool Chaining/Injection (Type 2)
✓Real documented attacks: AgentFlayer, Amazon Q DNS exfil, MCP descriptor poisoning, EDR bypass via tool chain
✓Why MCP expanded the ASI02 attack surface and what tool descriptor poisoning looks like
✓The root cause: authorization and intent are separated in agentic systems
✓7 mitigations and which ones stop which attacks — with the matrix to prove it