A new research warning points to a dangerous pattern in agentic security tools: if untrusted content can steer the agent, the defender itself may become an execution path.
A proof-of-concept called Friendly Fire highlights a sharper risk in agentic security: the tool meant to inspect hostile code can be steered into executing it.