攻击arXiv 2608.27800·8月28日ContextLeak:通过恶意工具窃取 LLM Agent 运行时上下文提出 ContextLeak,用强化学习生成恶意工具描述以诱导 Agent 外泄上下文arXiv2608.27800发表8月28日层应用层场景AI Agent测试Qwen-3-8B、GPT-OSS-20B、Gemma-4-E4B-it 等 11 个攻击提示注入技术诱导选用组件MCP 与技能+1+1深度解读完整解读