AI Agent Tool Invocation Hijacked via Prompt Injection

Detects anomalous AI agent behavior where the agent ingests untrusted external content (e.g., tool outputs, RAG retrievals, or web fetches) and subsequently invokes high-risk or sensitive capabilities (such as shell execution, secret reading, or unauthorized network calls) within the same session. This pattern is indicative of an indirect prompt injection attack attempting to leverage the agent's internal tool-calling mechanisms for unauthorized actions.