🐦 Twitter Post Details

Viewing enriched Twitter post

@dair_ai

// ContextLeak in AI Agents // The whole attack surface here is a tool name and a tool description. Stealing an LLM agent's runtime context, meaning the user prompt, the execution trajectory and the tool list, needs three things to line up. The agent has to pick the malicious tool, it has to pass its context in as arguments, and the tool has to forward that anywhere the attacker wants. Existing work covers the first and third conditions and leaves the second one mostly alone. ContextLeak targets the middle step. Researchers at Duke use an attack LLM to generate the malicious tool's name and description, then fine-tune that LLM with reinforcement learning on a set of shadow users with diverse simulated agent contexts. The reward functions are built specifically for the exfiltration objective. It remains highly effective when the shadow contexts differ substantially from the victim's, and it outperforms existing malicious-tool attacks adapted to this setting. Paper: https://t.co/UBeXFTvEXu Chat with Paper: https://t.co/hs6H72omPJ

Media 1

📊 Media Metadata

{
  "media": [
    {
      "type": "photo",
      "url": "https://crmoxkoizveukayfjuyo.supabase.co/storage/v1/object/public/media/posts/2094555336892145909/media_0.jpg",
      "filename": "media_0.jpg"
    }
  ],
  "processed_at": "2026-08-31T23:02:21.201058",
  "pipeline_version": "2.0"
}

🔧 Raw API Response

{
  "type": "tweet",
  "id": "2094555336892145909",
  "url": "https://x.com/dair_ai/status/2094555336892145909",
  "twitterUrl": "https://twitter.com/dair_ai/status/2094555336892145909",
  "text": "// ContextLeak in AI Agents //\n\nThe whole attack surface here is a tool name and a tool description.\n\nStealing an LLM agent's runtime context, meaning the user prompt, the execution trajectory and the tool list, needs three things to line up.\n\nThe agent has to pick the malicious tool, it has to pass its context in as arguments, and the tool has to forward that anywhere the attacker wants.\n\nExisting work covers the first and third conditions and leaves the second one mostly alone.\n\nContextLeak targets the middle step.\n\nResearchers at Duke use an attack LLM to generate the malicious tool's name and description, then fine-tune that LLM with reinforcement learning on a set of shadow users with diverse simulated agent contexts. The reward functions are built specifically for the exfiltration objective.\n\nIt remains highly effective when the shadow contexts differ substantially from the victim's, and it outperforms existing malicious-tool attacks adapted to this setting.\n\nPaper: https://t.co/UBeXFTvEXu\n\nChat with Paper: https://t.co/hs6H72omPJ",
  "source": "Twitter for iPhone",
  "retweetCount": 1,
  "replyCount": 3,
  "likeCount": 11,
  "quoteCount": 1,
  "viewCount": 1373,
  "createdAt": "Mon Aug 31 22:38:01 +0000 2026",
  "lang": "en",
  "bookmarkCount": 8,
  "isReply": false,
  "inReplyToId": null,
  "conversationId": "2094555336892145909",
  "displayTextRange": [
    0,
    279
  ],
  "inReplyToUserId": null,
  "inReplyToUsername": null,
  "author": {
    "type": "user",
    "userName": "dair_ai",
    "url": "https://x.com/dair_ai",
    "twitterUrl": "https://twitter.com/dair_ai",
    "id": "889050642903293953",
    "name": "DAIR.AI",
    "isVerified": false,
    "isBlueVerified": true,
    "verifiedType": null,
    "profilePicture": "https://pbs.twimg.com/profile_images/1643277398522187778/31dedbLo_normal.jpg",
    "coverPicture": "https://pbs.twimg.com/profile_banners/889050642903293953/1773242460",
    "description": "",
    "location": "",
    "followers": 130931,
    "following": 1,
    "status": "",
    "canDm": true,
    "canMediaTag": true,
    "createdAt": "Sun Jul 23 09:12:45 +0000 2017",
    "entities": {
      "description": {
        "urls": []
      },
      "url": {}
    },
    "fastFollowersCount": 0,
    "favouritesCount": 5157,
    "hasCustomTimelines": true,
    "isTranslator": false,
    "mediaCount": 340,
    "statusesCount": 3676,
    "withheldInCountries": [],
    "affiliatesHighlightedLabel": {},
    "possiblySensitive": false,
    "pinnedTweetIds": [
      "2094472291002589452"
    ],
    "profile_bio": {
      "description": "Democratizing AI research, education, and technologies. Learn about AI Agents for FREE at https://t.co/HHXg8rryu4",
      "entities": {
        "description": {
          "urls": [
            {
              "display_url": "academy.dair.ai/courses/elemen…",
              "expanded_url": "https://academy.dair.ai/courses/elements-of-ai-agents",
              "indices": [
                90,
                113
              ],
              "url": "https://t.co/HHXg8rryu4"
            }
          ]
        },
        "url": {
          "urls": [
            {
              "display_url": "dair.ai",
              "expanded_url": "https://www.dair.ai/",
              "indices": [
                0,
                23
              ],
              "url": "https://t.co/lkqPZtMU5s"
            }
          ]
        }
      }
    },
    "isAutomated": false,
    "automatedBy": null
  },
  "extendedEntities": {
    "media": [
      {
        "display_url": "pic.x.com/FnPtrwdBcX",
        "expanded_url": "https://x.com/dair_ai/status/2094555336892145909/photo/1",
        "ext_master_playlist_only": [],
        "ext_media_availability": {
          "status": "Available"
        },
        "ext_playlists": [],
        "features": {
          "large": {
            "faces": []
          },
          "orig": {
            "faces": []
          }
        },
        "id_str": "2094555333146644480",
        "indices": [
          280,
          303
        ],
        "media_key": "3_2094555333146644480",
        "media_results": {
          "id": "QXBpTWVkaWFSZXN1bHRzOgwAAQoAAR0RWvpimxAACgACHRFa+0Ha4PUAAA==",
          "result": {
            "__typename": "ApiMedia",
            "id": "QXBpTWVkaWE6DAABCgABHRFa+mKbEAAKAAIdEVr7Qdrg9QAA",
            "media_key": "3_2094555333146644480"
          }
        },
        "media_url_https": "https://pbs.twimg.com/media/HRFa-mKbEAA1njh.jpg",
        "original_info": {
          "focus_rects": [
            {
              "h": 925,
              "w": 1652,
              "x": 0,
              "y": 0
            },
            {
              "h": 1652,
              "w": 1652,
              "x": 0,
              "y": 0
            },
            {
              "h": 1878,
              "w": 1647,
              "x": 0,
              "y": 0
            },
            {
              "h": 1878,
              "w": 939,
              "x": 0,
              "y": 0
            },
            {
              "h": 1878,
              "w": 1652,
              "x": 0,
              "y": 0
            }
          ],
          "height": 1878,
          "width": 1652
        },
        "sizes": {
          "large": {
            "h": 1878,
            "w": 1652
          }
        },
        "type": "photo",
        "url": "https://t.co/FnPtrwdBcX"
      }
    ]
  },
  "card": null,
  "place": {},
  "entities": {
    "hashtags": [],
    "symbols": [],
    "urls": [
      {
        "display_url": "arxiv.org/abs/2608.27800",
        "expanded_url": "https://arxiv.org/abs/2608.27800",
        "indices": [
          987,
          1010
        ],
        "url": "https://t.co/UBeXFTvEXu"
      },
      {
        "display_url": "academy.dair.ai/papers/context…",
        "expanded_url": "https://academy.dair.ai/papers/contextleak-exfiltrating-llm-agent-context-via-malicious-tools-2608.27800",
        "indices": [
          1029,
          1052
        ],
        "url": "https://t.co/hs6H72omPJ"
      }
    ],
    "user_mentions": []
  },
  "quoted_tweet": null,
  "retweeted_tweet": null,
  "isLimitedReply": false,
  "communityInfo": null,
  "article": null
}