MITRE ATLAS Mapped 2026 – Top AI Triggered Agentic Prompt Injection Detection (AML.T0051.002)

Detects autonomous AI agents triggered by routine, non-interactive workflows (such as scheduled tasks, tickets, or calendar invites) that subsequently invoke sensitive tools. The rule correlates these invocations with content hashes previously flagged as containing malicious indirect prompt injections, indicating an attack where a payload remains dormant until processed by an automated agent.