●builderYou need to implement stricter validation on tool selection outputs to prevent agents from executing unauthorized functions.
●policyThis reveals a new attack surface in agentic workflows that extends beyond traditional prompt-based safety risks.