Back to Topic Hubs
AI SecurityTopic HubAugust 3, 2026Yellow — detail controls

Agentic AI Security: Prompt Injection, Tool Hijacking, and Voice Agents

Quick Answer

This topic gathers richards.ai's work on what changes when LLMs gain tools, memory, and peer agents: multi-agent prompt injection, tool hijacking, memory poisoning, and voice-agent variants. The cluster treats these as one authority-propagation problem, and offers reading paths for practitioners (checklist), leadership (executive brief), researchers (source papers), and newcomers (explainers and glossary).

Agentic AI Security: Prompt Injection, Tool Hijacking, and Voice Agents

This topic collects everything richards.ai has published on securing agentic AI systems — LLMs with tools, memory, and peer agents. The artifacts cluster around one observation: prompt injection in agentic systems is a confused-deputy and authority-propagation problem, not a string-filtering problem. The new hardening paper is now the canonical defense reference for the cluster and supersedes the earlier exploitation paper, which remains listed for historical context. Some reproduction detail is withheld in the linked artifacts per per-artifact risk controls.

What this topic covers

In scope: multi-agent prompt injection and its named sub-classes — cross-agent infection, memory poisoning, tool hijacking — plus the retrieval and voice-modality variants of the same authority-confusion pattern. The cluster spans threat models, engineered defenses, glossary terms, an operational checklist, and a live tool. Out of scope: single-agent jailbreaking that involves no tools, memory, or inter-agent channels, and vendor-specific deployment guidance for any one orchestration framework.

How to read this page

Newcomers should start with the multi-agent prompt injection explainer, which frames the threat model the rest of the cluster assumes, then branch into the tool-side, retrieval, and voice explainers as needed. Practitioners reviewing or building a system should work directly from the defense checklist, which operationalizes the hardening paper's controls. Engineering leads and security leadership who will not read the full paper get the same conclusions in the executive brief. Researchers should read the two papers in publication order — exploitation first, then hardening — to see how the defensive architecture answers the attack taxonomy.

Where this topic sits

This cluster sits inside the security pillar and is the largest topic on the site to date; sibling clusters live on the topics index. The source research it curates, along with work outside this cluster, is collected on the papers index.

Papers

2 members

Learn

4 members

Glossary

4 members

Checklists

1 member

Briefs

1 member

Tools

1 member