control
NIST-TEVV-06 — Test agent tool misuse and unauthorized external actions
Appendix B includes tests for misuse of connected tools and external actions, including unsafe tool selection, excessive agency, unauthorized action attempts, and harmful task execution.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- framework
- nist-ai-tevv-athlon
- type
- detective
- category
- technical
Details
- control_id
- NIST-TEVV-06
- framework
- nist-ai-tevv-athlon
- group
- AI Evaluation and Agent Security Testing
- domains
- risk_count
- 0
- control_type
- detective
- control_category
- technical
- automation
- hybrid
- key_control
- False
- requirement_status
- Not provided
- requirement_frequency
- Not provided
- source_url
- https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.200-2.ipd.pdf#page=32
- source_pages
- NIST AI 200-2 ipd Appendix B, Table 4, p. 24: Agent / tool abuse testing
- statement
- Appendix B includes tests for misuse of connected tools and external actions, including unsafe tool selection, excessive agency, unauthorized action attempts, and harmful task execution.
Source
Connections
- UC-VULN-02 — Test security through independent penetration exercises informed_by NIST-TEVV-06 — Test agent tool misuse and unauthorized external actions
- framework
- nist-ai-tevv-athlon
- control_id
- NIST-TEVV-06
- coverage
- guidance
- relationship
- informs
- delta
- Not provided
- source_version
- NIST AI 200-2 ipd (Initial Public Draft), August 2026
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- sourcePages
- NIST AI 200-2 ipd Appendix B, Table 4, p. 24: Agent / tool abuse testing
- NIST-TEVV-06 — Test agent tool misuse and unauthorized external actions belongs_to NIST TEVV-Athlon (draft, Aug 2026)
- UC-AI-19 — Constrain agent actions and tool use to authorized scope informed_by NIST-TEVV-06 — Test agent tool misuse and unauthorized external actions
- framework
- nist-ai-tevv-athlon
- control_id
- NIST-TEVV-06
- coverage
- guidance
- relationship
- informs
- delta
- Not provided
- source_version
- NIST AI 200-2 ipd (Initial Public Draft), August 2026
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- sourcePages
- NIST AI 200-2 ipd Appendix B, Table 4, p. 24: Agent / tool abuse testing