Skip to content

Hide Navigation Hide TOC

Tool Schema Enumeration via Social Engineering - ATR-2026-01303 (dd0c2c6f-169b-53b1-b7d7-6861c80ab928)

Detects attempts to extract full tool schemas, internal API endpoints, and function signatures from an agent through social engineering. Attackers use authority framing ("I'm the CEO", "trusted QA analyst", "performing security audit"), disability framing ("I am VERY autistic, I can only understand python scripts"), technical output formatting pressure (JSON schema format, OpenAPI output), or operational pretexts to elicit complete tool manifests including admin-only functions. Unlike legitimate "what can you help me with?" questions, these payloads demand structured technical output with parameter types, input schemas, and full capability listings — the exact information needed to craft targeted attacks. Observed in tool-schema-extraction corpus (21 probes) and tool-discovery-mcp-unauth corpus (6 probes).

Cluster A Galaxy A Cluster B Galaxy B Level
Tool Schema Enumeration via Social Engineering - ATR-2026-01303 (dd0c2c6f-169b-53b1-b7d7-6861c80ab928) Agent Threat Rules LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern 1