
ai-security · 6 min
Confused deputy: when an LLM with tools obeys the wrong web page
The user asks the agent to summarise a URL. The page has embedded instructions that trigger another tool — send_email — with conversation data. The model complies without asking. Reproducible PoC with OpenAI function calling.
· Manuel López Pérez




