Tool Misuse — Privilege Escalation via Social Engineering Agent to Grant Access - ATR-2026-00720 (12f67cd7-81cd-52f4-98a5-0210d99db1e7)
Detects requests where a user socially engineers an agent with access control tools to grant unauthorized access: inviting users to Slack workspaces and channels, granting delivery personnel house access for plausible pretexts, adding users to calendars or CRM systems with excessive permissions. The attacker provides a plausible social justification to bypass normal access control review. Source: tool-misuse-privilege-escalation (ToolEmu corpus).