RAG Knowledge Base / Vector Store Poisoning Targeting AI Agent

Detects potential poisoning of an AI agent's RAG knowledge base or vector store through suspicious bulk ingestion or injection of imperative instruction-style content. The rule correlates these ingestion events with subsequent anomalous tool usage patterns by the same agent session, indicating a possible prompt injection or data manipulation attack aimed at altering agent behavior.