MITRE ATLAS Mapped 2026 Top AI Agent Security Detection – AI Agent Context Poisoning (AML.T0080)

Detects attempts to perform context or memory poisoning against an AI agent by injecting imperative, instruction-like payloads into the agent's long-term memory or context store. The rule specifically monitors updates originating from untrusted channels, such as tool outputs, external documents, or web content, which contain patterns commonly associated with prompt injection attacks (e.g., overriding system instructions or role definitions).