{"data":{"id":"e9d49445-7f6b-43f0-bec5-e14709c13a64","title":"Datura: Progressive Red Teaming Testing for Tool Invocation Chain in LLM Agents","summary":"Researchers study how LLM agents that call external tools can be exploited when they implicitly trust tool outputs and metadata. They present Datura, an automated red teaming framework that builds chained tool manipulations, where each step looks legitimate but the sequence leads to harmful outcomes. Across five LLMs and 740 safety-critical tasks, Datura reports 94.86 to 99.59% attack success rate under Model Alignment and 78.78 to 95.54% under Prompt Refuge. The paper appeared in Proceedings of the ACM on Software Engineering on 2026-10-01.","solution":"N/A -- no mitigation discussed in source.","labels":["security","research"],"sourceUrl":"https://doi.org/10.1145/3832101","publishedAt":"2026-10-01T00:00:00.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"info","attackType":["jailbreak"],"issueType":"research","affectedPackages":null,"affectedPackageNames":null,"affectedPackageRefs":null,"affectedVendors":[],"affectedVendorsRaw":[],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":null,"disclosureDate":"2026-10-01T00:00:00.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["safety","integrity"],"aiComponentTargeted":"agent","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":"peer_reviewed","atlasIds":null}}