From Recon to Free Flights: Precision Prompt Attacks on AI Agents
Akamai Technologies, Friday, July 17th, 2026
Akamai researchers walk through a kill chain in which attackers spoof tool output to make an AI travel agent issue free flights.
Akamai security researcher Guy Amit details a step-by-step attack against an AI travel booking agent, beginning with system reconnaissance to map the agent's available tools and instructions.
The attacker then uses precision prompt injection and tool output spoofing to make the agent believe fraudulent booking confirmations are legitimate.
The result is a chain that ultimately issues flights at no cost, demonstrating how agentic systems extend trust to data they should treat as untrusted. Akamai argues that conventional input filtering is insufficient because the abuse occurs at the tool-response boundary rather than the user prompt.