{"success":true,"data":{"id":"agent-tool-permission-creep","label":"Spoofed notification claiming an AI assistant / agentic tool needs expanded OAuth/tool permissions. \"Approve expanded permissions within 24 hours: grant access to your calendar, email, and file storage.\" Targets users of AI assistants (ChatGPT, Copilot, Claude, Gemini). Sender NOT a canonical AI vendor (anthropic.com, openai.com, google.com, microsoft.com, etc.). Label-only: engine flags but cannot patch the agent platform — action is always label, never trash. Source: Red-Team R8 multi-agent council C5 (agentic-AI specialist).","description":"Spoofed notification claiming an AI assistant or agentic tool requires expanded OAuth/tool permissions. Urges the user to \"approve expanded permissions within 24 hours: grant access to calendar, email, and file storage.\" Targets users of AI assistants (ChatGPT, Copilot, Claude, Gemini). Sender is NOT a canonical AI vendor (anthropic.com, openai.com, google.com, microsoft.com). This is an OAuth-scope / tool-permission expansion pretext distinct from the mcp-shared-prompt-poisoning-lure (which targets system_prompt injection). Label-only signal (invoice +5): the engine cannot patch the agent platform but must surface the email and refuse silent delete. Source: Red-Team R8 multi-agent council C5 (agentic-AI specialist).","tier":"warning","category":"other","isThin":false}}