STAC: LLM Agent Tool Chaining Attacks

Arxiv pdf 2025-09-01T00:00:00
arXiv Paper — PDF not available. Only the Executive Summary is available here. To read or download the full paper, visit the arXiv abstract page.

Abstract

As LLM agents gain the ability to interact with the digital world via tools, they introduce security vulnerabilities beyond traditional text-based safety concerns. This paper introduces Sequential Tool Attack Chaining (STAC), an automated framework that orchestrates sequences of seemingly innocuous tool calls which, while benign in isolation, collectively enable harmful environmental changes. Evaluating state-of-the-art agents including GPT-4.1, the researchers found an average attack success rate (ASR) of 91.2%, demonstrating that existing prompt-based defenses are insufficient and that protecting tool-enabled agents requires reasoning over cumulative action sequences rather than isolated prompts.

Loading executive summary...

LINK COPIED TO CLIPBOARD