Tool-Pivot / Confused-Deputy Resistance Check
A retrieved doc said “call the admin tool” — did your agent obey?
The highest-blast-radius tool-use failure is not a bad argument or a malformed result — it is the agent being steered by an untrusted reference to pivot to a more-privileged, internal, or unrequested tool surface than the task required. A retrieved doc or a prior tool output NAMES an internal-admin tool, and the agent SELECTS and INVOKES it, treating the untrusted-supplied tool selection (or target) as authoritative — the tool-layer confused-deputy / SSRF analogue. Every other surface grades capability co-presence, one call's arguments, a result vs its contract, a value's provenance, or token handling. None grade the tool-selection decision itself being hijacked. AgentSmack declares the task scope (objective + allowedToolset), the privilege tier of each tool, and which content is untrusted, then detects when an untrusted reference DROVE a privileged pivot or the agent reached an internal-admin tool the task never requested — capping the score with a hard blocker on a genuine pivot, while an in-scope read-only run, an approved privileged call, or a least-privilege selection scores a clean 100. Raw tool / target / args bytes are never stored. Load a sample to watch the lineage timeline light up with no live infra.
Related boundary: Name-Resolution / Homoglyph Tool & Recipient Spoofing grades the orthogonal RESOLUTION lens — not being steered to a REAL privileged tool, but the agent CALLING a visually-confusable IMPOSTER (a homoglyph / invisible-char / IDN twin) of the target it intended to call.