Agent Plan Poisoning: When Injected Content Rewrites an Agent's Own Task List
Agent plan poisoning is SSA descriptive wording for injected content that rewrites an agent's own live task or plan object, adding, reordering, or completing steps the user never approved, so a later step executes with the authority the user granted the original plan. Covers the documented Auto-GPT indirect-injection CVEs and the AgentDojo benchmark, with detection and containment for agents that maintain a persistent, tool-visible task list.
Target: Plans & ArtifactsPersistence: Session to Cross-Session