{
  "$schema": "https://aisharedresponsibility.com/data/attack-inventory.schema.json",
  "inventory_version": "0.1.0",
  "updated": "2026-10-01",
  "description": "Inventory of published attack classes against AI and agentic systems. Each entry states a failure mode and carries catalog, paper, and incident ids that were checked against a pinned source. A claims-test run can load this file as a pinned source in its C-attacks step instead of recalling ids from memory. Threat definitions belong to their source catalogs; accountability for each class joins to the SRF threat crosswalk at /data/threats.json through srf_crosswalk.",
  "scope": "Attack classes against AI models, LLM applications, and agentic systems, plus classical weakness classes that return when model output or an agent tool call reaches a shell, browser, database, file system, or network fetch. The scope field on each entry is ai, agentic, or classical-reopened.",
  "rules": [
    "Describe the failure mode only: who loses what, under what condition. No reproduction steps, payloads, or attack procedures.",
    "A ref is verified only after its source was opened and the entry records the date and method. Memory is never verification.",
    "verified on a paper ref means the id resolves and the title and first author match. It does not mean the paper was read in full.",
    "Every taxonomy ref records its catalog version, and the catalogs block pins each version.",
    "Ids are stable atk- slugs. A retired id is never reused; set status to merged or withdrawn instead.",
    "ATT-nn ids and draft_overlap belong to one assessment and are not stored here.",
    "mapping_quality is exact when the catalog text covers the class without stretching, closest when it covers part of the class or an adjacent class and is the best entry available, and analogy when it describes a different mechanism with a similar effect.",
    "Versioning is semver: patch for ref fixes, minor for added entries, major for removed fields or id changes. Every entry change adds one changelog line naming the id and the reason.",
    "Recheck triggers: a new ATLAS release, a revision of the OWASP LLM Top 10 or of OWASP Agentic AI Threats and Mitigations, a new incident cited in a CoSAI WS2 draft, or a claims-test run that finds a class missing here."
  ],
  "catalogs": {
    "mitre-atlas": {
      "name": "MITRE ATLAS",
      "version": "v2026.08",
      "released": "2026-09-01",
      "source_url": "https://github.com/mitre-atlas/atlas-data/blob/v2026.08/dist/v6/ATLAS-2026.08.yaml",
      "source_commit": "41d4f5ca4112f0e492ffaa3ebff07dc80a75afa5",
      "content_sha256": "a8d32f676854cc57721c217ec5b39f07db518076dee4a6c1335df0a7bc8271a2",
      "retrieved_on": "2026-10-01",
      "id_form": "AML.Tnnnn or AML.Tnnnn.nnn for techniques; AML.CSnnnn for case studies",
      "title_convention": "Sub-technique titles are recorded as parent name, colon, sub-technique name.",
      "newer_release_seen": {
        "version": "v2026.09",
        "checked_on": "2026-10-01",
        "cited_ids_changed": 0,
        "note": "Every cited technique and case-study id keeps its name in v2026.09. That release adds 11 techniques, including AML.T0129 Triggers in Multimodal Inputs."
      }
    },
    "owasp-llm-top10": {
      "name": "OWASP Top 10 for LLM Applications",
      "version": "2025",
      "released": "2024-11",
      "source_url": "https://genai.owasp.org/llm-top-10/",
      "retrieved_on": "2026-10-01",
      "id_form": "LLMnn:2025"
    },
    "owasp-agentic-threats": {
      "name": "OWASP Agentic AI - Threats and Mitigations",
      "version": "1.1",
      "released": "2025-12",
      "source_url": "https://genai.owasp.org/download/45674/?tmstv=1739819891",
      "content_sha256": "65e3bd59f99c411b055c6caf2bac96ab361dff8c010e4bef532a593ce10345ff",
      "retrieved_on": "2026-10-01",
      "id_form": "Tn, T1 to T17",
      "license_note": "CC BY-SA 4.0. This file cites ids and titles only."
    },
    "owasp-dsgai": {
      "name": "OWASP GenAI Data Security Risks and Mitigations",
      "version": "1.0",
      "released": "2026",
      "source_url": "https://github.com/GenAI-Security-Project/GenAI-Data-Security-Initiative/blob/b9525a58ec74ef34713f03676bd3bb354c9be426/datasets/_shared/dsgai_taxonomy.json",
      "source_commit": "b9525a58ec74ef34713f03676bd3bb354c9be426",
      "content_sha256": "0e0366209cab6f6b91abe60311813a28f169132de636e79b505eeb44429d6598",
      "retrieved_on": "2026-10-01",
      "id_form": "DSGAInn",
      "license_note": "CC BY-SA 4.0. This file cites ids and names only."
    },
    "cwe": {
      "name": "Common Weakness Enumeration",
      "version": "4.20",
      "released": "2026-04-30",
      "source_url": "https://cwe-api.mitre.org/api/v1/cwe/version",
      "retrieved_on": "2026-10-01",
      "id_form": "CWE-n"
    }
  },
  "verification_methods": {
    "atlas-release-yaml": "Downloaded dist/v6/ATLAS-2026.08.yaml at tag v2026.08 from github.com/mitre-atlas/atlas-data, recorded its SHA-256, and looked up each technique and case-study id and its name. Each case-study ref was confirmed to employ the technique named in the entry, using the release's relationships block.",
    "atlas-next-release-diff": "Downloaded ATLAS-2026.09.yaml at tag v2026.09 and confirmed each cited id keeps its name.",
    "owasp-llm-pages": "Fetched genai.owasp.org/llm-top-10/ to match each id and title, then read the cited risk page for the passage that supports the mapping.",
    "owasp-agentic-pdf": "Downloaded the Agentic AI Threats and Mitigations PDF (cover: Version 1.1, December 2025), recorded its SHA-256, and read the threat table row for each cited T id.",
    "dsgai-taxonomy-json": "Fetched datasets/_shared/dsgai_taxonomy.json at the pinned commit and matched each id, name, and summary.",
    "cwe-api": "Queried cwe-api.mitre.org for each CWE id and for the content version.",
    "arxiv-api": "Queried export.arxiv.org/api/query by id_list and matched title, first author, and first-version year.",
    "venue-page": "Fetched the venue's presentation page and matched the title.",
    "cve-services-api": "Queried cveawg.mitre.org/api/cve/<id>, confirmed state PUBLISHED, and matched vendor and product.",
    "url-fetch": "Fetched the URL and confirmed HTTP 200 on the access date. A URL has no stable id, so recheck it on each review.",
    "crosswalk-lookup": "Confirmed each srf_crosswalk id exists in /data/threats.json. build/verify_attack_inventory.py repeats this check."
  },
  "export_contract": {
    "target": "claims-test C-attacks rows",
    "pack_version": "1.0.8",
    "rules": [
      "build/export_attack_inventory.py writes one row per active entry, in inventory order, numbered ATT-01 upward after any --topics, --scope, or --ids filter.",
      "taxonomy_ref is the best verified ref: exact before closest before analogy, and within one grade ATLAS, then OWASP LLM, OWASP Agentic, DSGAI, and CWE. OWASP Agentic ids print with a catalog prefix and version. It is null when the entry has no taxonomy ref.",
      "paper_ref is the first verified paper as arXiv:<id>, else the first verified CVE or ATLAS case-study id, else null.",
      "evidence is pinned. citation_status is resolved_pinned when every emitted ref is verified and unresolved_unpinned otherwise.",
      "draft_overlap and stage are null in the export. The run judges overlap against its own draft.",
      "Each row adds inventory_id, the atk- id it came from, so a reviewer can trace the row back to its entry."
    ]
  },
  "changelog": [
    {
      "version": "0.1.0",
      "date": "2026-10-01",
      "id": "*",
      "change": "First release. 31 entries seeded from the Published attack classes table of claims-test assessment ct-20261001-telemetry-rfc-v06-r2, plus 6 classical-reopened entries. Every ref was checked against its pinned source on 2026-10-01."
    },
    {
      "version": "0.1.0",
      "date": "2026-10-01",
      "id": "atk-indirect-prompt-injection",
      "change": "The seed row listed EchoLeak (CVE-2025-32711) here; refs updated, see verification notes."
    },
    {
      "version": "0.1.0",
      "date": "2026-10-01",
      "id": "atk-zero-click-output-exfiltration",
      "change": "The seed row cited AML.T0057 only; refs updated, see verification notes."
    },
    {
      "version": "0.1.0",
      "date": "2026-10-01",
      "id": "atk-encoded-input-guardrail-evasion",
      "change": "The seed row cited AML.T0015 only; refs updated, see verification notes."
    },
    {
      "version": "0.1.0",
      "date": "2026-10-01",
      "id": "atk-telemetry-store-disclosure",
      "change": "The seed row cited LLM02:2025 only; refs updated, see verification notes."
    },
    {
      "version": "0.1.0",
      "date": "2026-10-01",
      "id": "atk-agent-memory-poisoning",
      "change": "The seed row reached MINJA and AgentPoison through the CoSAI incident-response document; refs updated, see verification notes."
    },
    {
      "version": "0.1.0",
      "date": "2026-10-01",
      "id": "atk-backdoored-model-trigger",
      "change": "The seed row cited AML.T0018, which ATLAS v2026.08 titles Manipulate AI Model; refs updated, see verification notes."
    },
    {
      "version": "0.1.0",
      "date": "2026-10-01",
      "id": "atk-malicious-model-artifact",
      "change": "The seed row cited the parent AML.T0010; refs updated, see verification notes."
    },
    {
      "version": "0.1.0",
      "date": "2026-10-01",
      "id": "atk-mcp-tool-poisoning",
      "change": "The seed row cited AML.T0051.001 and an Invariant Labs post with no stable id; refs updated, see verification notes."
    },
    {
      "version": "0.1.0",
      "date": "2026-10-01",
      "id": "atk-sandbox-escape",
      "change": "The seed row used OWASP Agentic T11 as the closest match; refs updated, see verification notes."
    },
    {
      "version": "0.1.0",
      "date": "2026-10-01",
      "id": "atk-unbounded-consumption",
      "change": "The seed row cited the parent AML.T0034; refs updated, see verification notes."
    },
    {
      "version": "0.1.0",
      "date": "2026-10-01",
      "id": "atk-telemetry-borne-injection-into-llm-triage",
      "change": "The seed row mapped this class by analogy with no paper; refs updated, see verification notes."
    }
  ],
  "entries": [
    {
      "id": "atk-indirect-prompt-injection",
      "name": "Indirect prompt injection",
      "aliases": [
        "cross-domain prompt injection",
        "XPIA"
      ],
      "family": "injection",
      "scope": "ai",
      "topics": [
        "tool-calling",
        "MCP"
      ],
      "failure_mode": "Content retrieved as data steers the model to act for the content's author against the user who invoked it.",
      "taxonomy_refs": [
        {
          "catalog": "mitre-atlas",
          "catalog_version": "v2026.08",
          "id": "AML.T0051.001",
          "title_in_catalog": "LLM Prompt Injection: Indirect",
          "mapping_quality": "exact",
          "verified": true
        },
        {
          "catalog": "owasp-llm-top10",
          "catalog_version": "2025",
          "id": "LLM01:2025",
          "title_in_catalog": "Prompt Injection",
          "mapping_quality": "exact",
          "verified": true
        }
      ],
      "paper_refs": [
        {
          "type": "arxiv",
          "id": "2302.12173",
          "title": "Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection",
          "first_author": "Greshake",
          "year": 2023,
          "venue": null,
          "verified": true
        }
      ],
      "incident_refs": [
        {
          "type": "atlas-case-study",
          "id": "AML.CS0040",
          "label": "Hacking ChatGPT's Memories with Prompt Injection",
          "catalog_version": "v2026.08",
          "verified": true
        }
      ],
      "srf_crosswalk": [
        "indirectpromptinjection"
      ],
      "related": [
        "atk-multimodal-instruction-injection",
        "atk-zero-click-output-exfiltration",
        "atk-telemetry-borne-injection-into-llm-triage",
        "atk-self-replicating-prompt",
        "atk-agent-memory-poisoning"
      ],
      "origin": "seed",
      "status": "active",
      "merged_into": null,
      "verification": {
        "checked_on": "2026-10-01",
        "checked_by": "AI agent in Cursor, session of 2026-10-01",
        "reviewed_by": null,
        "methods": [
          "atlas-release-yaml",
          "atlas-next-release-diff",
          "owasp-llm-pages",
          "arxiv-api",
          "crosswalk-lookup"
        ],
        "notes": "The seed row listed EchoLeak (CVE-2025-32711) here. ATLAS case study AML.CS0059 tags the EchoLeak injection step as AML.T0051.002 Triggered, not .001 Indirect, so EchoLeak now sits under atk-zero-click-output-exfiltration. The RFC appendix A.5 row for TA-01 cites .001 and should be rechecked."
      },
      "added_in": "0.1.0",
      "last_changed_in": "0.1.0"
    },
    {
      "id": "atk-zero-click-output-exfiltration",
      "name": "Zero-click exfiltration through output or egress",
      "aliases": [],
      "family": "exfiltration",
      "scope": "ai",
      "topics": [
        "tool-calling"
      ],
      "failure_mode": "Model output carries internal data to an attacker-chosen destination with no user action.",
      "taxonomy_refs": [
        {
          "catalog": "mitre-atlas",
          "catalog_version": "v2026.08",
          "id": "AML.T0077",
          "title_in_catalog": "LLM Response Rendering",
          "mapping_quality": "exact",
          "verified": true
        },
        {
          "catalog": "mitre-atlas",
          "catalog_version": "v2026.08",
          "id": "AML.T0057",
          "title_in_catalog": "LLM Data Leakage",
          "mapping_quality": "closest",
          "verified": true
        },
        {
          "catalog": "owasp-llm-top10",
          "catalog_version": "2025",
          "id": "LLM05:2025",
          "title_in_catalog": "Improper Output Handling",
          "mapping_quality": "closest",
          "verified": true
        },
        {
          "catalog": "owasp-dsgai",
          "catalog_version": "1.0",
          "id": "DSGAI01",
          "title_in_catalog": "Sensitive Data Leakage",
          "mapping_quality": "closest",
          "verified": true
        }
      ],
      "paper_refs": [
        {
          "type": "arxiv",
          "id": "2509.10540",
          "title": "EchoLeak: The First Real-World Zero-Click Prompt Injection Exploit in a Production LLM System",
          "first_author": "Reddy",
          "year": 2025,
          "venue": null,
          "verified": true
        }
      ],
      "incident_refs": [
        {
          "type": "cve",
          "id": "CVE-2025-32711",
          "label": "EchoLeak, Microsoft 365 Copilot",
          "verified": true
        },
        {
          "type": "atlas-case-study",
          "id": "AML.CS0059",
          "label": "EchoLeak: Zero-Click Prompt Injection Targeting M365 Copilot for Data Exfiltration",
          "catalog_version": "v2026.08",
          "verified": true
        }
      ],
      "srf_crosswalk": [
        "disclosureinoutput"
      ],
      "related": [
        "atk-indirect-prompt-injection",
        "atk-llm-output-cross-site-scripting"
      ],
      "origin": "seed",
      "status": "active",
      "merged_into": null,
      "verification": {
        "checked_on": "2026-10-01",
        "checked_by": "AI agent in Cursor, session of 2026-10-01",
        "reviewed_by": null,
        "methods": [
          "atlas-release-yaml",
          "atlas-next-release-diff",
          "owasp-llm-pages",
          "dsgai-taxonomy-json",
          "arxiv-api",
          "cve-services-api",
          "crosswalk-lookup"
        ],
        "notes": "The seed row cited AML.T0057 only. AML.T0077 LLM Response Rendering describes the rendered-output channel, and AML.CS0059 employs it."
      },
      "added_in": "0.1.0",
      "last_changed_in": "0.1.0"
    },
    {
      "id": "atk-adversarial-suffix-jailbreak",
      "name": "Optimized adversarial-suffix jailbreak",
      "aliases": [
        "GCG"
      ],
      "family": "jailbreak",
      "scope": "ai",
      "topics": [],
      "failure_mode": "Crafted input defeats safety training, and the model produces output its policy forbids.",
      "taxonomy_refs": [
        {
          "catalog": "mitre-atlas",
          "catalog_version": "v2026.08",
          "id": "AML.T0054",
          "title_in_catalog": "LLM Jailbreak",
          "mapping_quality": "exact",
          "verified": true
        },
        {
          "catalog": "mitre-atlas",
          "catalog_version": "v2026.08",
          "id": "AML.T0043.000",
          "title_in_catalog": "Craft Adversarial Data: White-Box Optimization",
          "mapping_quality": "closest",
          "verified": true
        },
        {
          "catalog": "owasp-llm-top10",
          "catalog_version": "2025",
          "id": "LLM01:2025",
          "title_in_catalog": "Prompt Injection",
          "mapping_quality": "exact",
          "verified": true
        }
      ],
      "paper_refs": [
        {
          "type": "arxiv",
          "id": "2307.15043",
          "title": "Universal and Transferable Adversarial Attacks on Aligned Language Models",
          "first_author": "Zou",
          "year": 2023,
          "venue": null,
          "verified": true
        }
      ],
      "incident_refs": [],
      "srf_crosswalk": [
        "directpromptinjection"
      ],
      "related": [
        "atk-multi-turn-jailbreak-escalation"
      ],
      "origin": "seed",
      "status": "active",
      "merged_into": null,
      "verification": {
        "checked_on": "2026-10-01",
        "checked_by": "AI agent in Cursor, session of 2026-10-01",
        "reviewed_by": null,
        "methods": [
          "atlas-release-yaml",
          "atlas-next-release-diff",
          "owasp-llm-pages",
          "arxiv-api",
          "crosswalk-lookup"
        ],
        "notes": "LLM01:2025 Scenario 8 describes an appended adversarial suffix."
      },
      "added_in": "0.1.0",
      "last_changed_in": "0.1.0"
    },
    {
      "id": "atk-multi-turn-jailbreak-escalation",
      "name": "Multi-turn escalation",
      "aliases": [
        "Crescendo"
      ],
      "family": "jailbreak",
      "scope": "ai",
      "topics": [],
      "failure_mode": "Each turn stays under per-message thresholds while the session reaches a forbidden output.",
      "taxonomy_refs": [
        {
          "catalog": "mitre-atlas",
          "catalog_version": "v2026.08",
          "id": "AML.T0054",
          "title_in_catalog": "LLM Jailbreak",
          "mapping_quality": "exact",
          "verified": true
        },
        {
          "catalog": "owasp-llm-top10",
          "catalog_version": "2025",
          "id": "LLM01:2025",
          "title_in_catalog": "Prompt Injection",
          "mapping_quality": "closest",
          "verified": true
        }
      ],
      "paper_refs": [
        {
          "type": "arxiv",
          "id": "2404.01833",
          "title": "Great, Now Write an Article About That: The Crescendo Multi-Turn LLM Jailbreak Attack",
          "first_author": "Russinovich",
          "year": 2024,
          "venue": null,
          "verified": true
        }
      ],
      "incident_refs": [],
      "srf_crosswalk": [
        "directpromptinjection"
      ],
      "related": [
        "atk-adversarial-suffix-jailbreak"
      ],
      "origin": "seed",
      "status": "active",
      "merged_into": null,
      "verification": {
        "checked_on": "2026-10-01",
        "checked_by": "AI agent in Cursor, session of 2026-10-01",
        "reviewed_by": null,
        "methods": [
          "atlas-release-yaml",
          "atlas-next-release-diff",
          "owasp-llm-pages",
          "arxiv-api",
          "crosswalk-lookup"
        ],
        "notes": "ATLAS v2026.08 has no multi-turn sub-technique under AML.T0054."
      },
      "added_in": "0.1.0",
      "last_changed_in": "0.1.0"
    },
    {
      "id": "atk-encoded-input-guardrail-evasion",
      "name": "Guardrail evasion by encoding or obfuscation",
      "aliases": [],
      "family": "evasion",
      "scope": "ai",
      "topics": [],
      "failure_mode": "The classifier sees an encoded form and passes it; the model decodes and follows it.",
      "taxonomy_refs": [
        {
          "catalog": "mitre-atlas",
          "catalog_version": "v2026.08",
          "id": "AML.T0068",
          "title_in_catalog": "LLM Prompt Obfuscation",
          "mapping_quality": "exact",
          "verified": true
        },
        {
          "catalog": "mitre-atlas",
          "catalog_version": "v2026.08",
          "id": "AML.T0015",
          "title_in_catalog": "Evade AI Model",
          "mapping_quality": "closest",
          "verified": true
        },
        {
          "catalog": "owasp-llm-top10",
          "catalog_version": "2025",
          "id": "LLM01:2025",
          "title_in_catalog": "Prompt Injection",
          "mapping_quality": "exact",
          "verified": true
        }
      ],
      "paper_refs": [],
      "incident_refs": [],
      "srf_crosswalk": [
        "directpromptinjection"
      ],
      "related": [
        "atk-multimodal-instruction-injection"
      ],
      "origin": "seed",
      "status": "active",
      "merged_into": null,
      "verification": {
        "checked_on": "2026-10-01",
        "checked_by": "AI agent in Cursor, session of 2026-10-01",
        "reviewed_by": null,
        "methods": [
          "atlas-release-yaml",
          "atlas-next-release-diff",
          "owasp-llm-pages",
          "crosswalk-lookup"
        ],
        "notes": "The seed row cited AML.T0015 only. AML.T0068 LLM Prompt Obfuscation names base64 and rot13 encoding that bypasses guardrails. LLM01:2025 Scenario 9 covers encoded and multilingual input."
      },
      "added_in": "0.1.0",
      "last_changed_in": "0.1.0"
    },
    {
      "id": "atk-multimodal-instruction-injection",
      "name": "Multimodal instruction injection",
      "aliases": [],
      "family": "multimodal",
      "scope": "ai",
      "topics": [
        "multimodal"
      ],
      "failure_mode": "Instructions carried in image or audio input pass text-only guardrails.",
      "taxonomy_refs": [
        {
          "catalog": "mitre-atlas",
          "catalog_version": "v2026.08",
          "id": "AML.T0051.001",
          "title_in_catalog": "LLM Prompt Injection: Indirect",
          "mapping_quality": "exact",
          "verified": true
        },
        {
          "catalog": "mitre-atlas",
          "catalog_version": "v2026.08",
          "id": "AML.T0068",
          "title_in_catalog": "LLM Prompt Obfuscation",
          "mapping_quality": "closest",
          "verified": true
        },
        {
          "catalog": "owasp-llm-top10",
          "catalog_version": "2025",
          "id": "LLM01:2025",
          "title_in_catalog": "Prompt Injection",
          "mapping_quality": "exact",
          "verified": true
        }
      ],
      "paper_refs": [
        {
          "type": "arxiv",
          "id": "2307.10490",
          "title": "Abusing Images and Sounds for Indirect Instruction Injection in Multi-Modal LLMs",
          "first_author": "Bagdasaryan",
          "year": 2023,
          "venue": null,
          "verified": true
        }
      ],
      "incident_refs": [],
      "srf_crosswalk": [
        "indirectpromptinjection"
      ],
      "related": [
        "atk-indirect-prompt-injection",
        "atk-encoded-input-guardrail-evasion"
      ],
      "origin": "seed",
      "status": "active",
      "merged_into": null,
      "verification": {
        "checked_on": "2026-10-01",
        "checked_by": "AI agent in Cursor, session of 2026-10-01",
        "reviewed_by": null,
        "methods": [
          "atlas-release-yaml",
          "atlas-next-release-diff",
          "owasp-llm-pages",
          "arxiv-api",
          "crosswalk-lookup"
        ],
        "notes": "ATLAS v2026.09 adds AML.T0129 Triggers in Multimodal Inputs. Review it as a narrower ref when the ATLAS pin moves past v2026.08."
      },
      "added_in": "0.1.0",
      "last_changed_in": "0.1.0"
    },
    {
      "id": "atk-system-prompt-extraction",
      "name": "System prompt extraction",
      "aliases": [],
      "family": "disclosure",
      "scope": "ai",
      "topics": [],
      "failure_mode": "The instruction configuration, and any secret in it, reaches a user through output.",
      "taxonomy_refs": [
        {
          "catalog": "mitre-atlas",
          "catalog_version": "v2026.08",
          "id": "AML.T0056",
          "title_in_catalog": "Extract LLM System Prompt",
          "mapping_quality": "exact",
          "verified": true
        },
        {
          "catalog": "mitre-atlas",
          "catalog_version": "v2026.08",
          "id": "AML.T0069.002",
          "title_in_catalog": "Discover LLM System Information: System Prompt",
          "mapping_quality": "closest",
          "verified": true
        },
        {
          "catalog": "owasp-llm-top10",
          "catalog_version": "2025",
          "id": "LLM07:2025",
          "title_in_catalog": "System Prompt Leakage",
          "mapping_quality": "exact",
          "verified": true
        }
      ],
      "paper_refs": [],
      "incident_refs": [],
      "srf_crosswalk": [
        "inputdataleak"
      ],
      "related": [
        "atk-agent-config-credential-exposure"
      ],
      "origin": "seed",
      "status": "active",
      "merged_into": null,
      "verification": {
        "checked_on": "2026-10-01",
        "checked_by": "AI agent in Cursor, session of 2026-10-01",
        "reviewed_by": null,
        "methods": [
          "atlas-release-yaml",
          "atlas-next-release-diff",
          "owasp-llm-pages",
          "crosswalk-lookup"
        ],
        "notes": ""
      },
      "added_in": "0.1.0",
      "last_changed_in": "0.1.0"
    },
    {
      "id": "atk-training-data-extraction",
      "name": "Training-data extraction and verbatim reproduction",
      "aliases": [
        "verbatim reproduction"
      ],
      "family": "disclosure",
      "scope": "ai",
      "topics": [],
      "failure_mode": "The model reproduces memorized data to a requester who should not see it.",
      "taxonomy_refs": [
        {
          "catalog": "mitre-atlas",
          "catalog_version": "v2026.08",
          "id": "AML.T0057",
          "title_in_catalog": "LLM Data Leakage",
          "mapping_quality": "exact",
          "verified": true
        },
        {
          "catalog": "owasp-llm-top10",
          "catalog_version": "2025",
          "id": "LLM02:2025",
          "title_in_catalog": "Sensitive Information Disclosure",
          "mapping_quality": "exact",
          "verified": true
        },
        {
          "catalog": "owasp-dsgai",
          "catalog_version": "1.0",
          "id": "DSGAI18",
          "title_in_catalog": "Inference & Data Reconstruction",
          "mapping_quality": "closest",
          "verified": true
        }
      ],
      "paper_refs": [
        {
          "type": "arxiv",
          "id": "2311.17035",
          "title": "Scalable Extraction of Training Data from (Production) Language Models",
          "first_author": "Nasr",
          "year": 2023,
          "venue": null,
          "verified": true
        }
      ],
      "incident_refs": [],
      "srf_crosswalk": [
        "disclosureinoutput"
      ],
      "related": [
        "atk-model-extraction-via-api"
      ],
      "origin": "seed",
      "status": "active",
      "merged_into": null,
      "verification": {
        "checked_on": "2026-10-01",
        "checked_by": "AI agent in Cursor, session of 2026-10-01",
        "reviewed_by": null,
        "methods": [
          "atlas-release-yaml",
          "atlas-next-release-diff",
          "owasp-llm-pages",
          "dsgai-taxonomy-json",
          "arxiv-api",
          "crosswalk-lookup"
        ],
        "notes": "The RFC appendix A.5 also tags AML.T0024.000 Infer Training Data Membership for this class. Membership inference tests whether a record was in training and does not reproduce it, so that id is not cited here."
      },
      "added_in": "0.1.0",
      "last_changed_in": "0.1.0"
    },
    {
      "id": "atk-telemetry-store-disclosure",
      "name": "Sensitive data disclosure through the telemetry store",
      "aliases": [],
      "family": "telemetry plane",
      "scope": "ai",
      "topics": [
        "telemetry"
      ],
      "failure_mode": "Prompts, tool arguments, and outputs captured for detection become a readable store of sensitive data.",
      "taxonomy_refs": [
        {
          "catalog": "owasp-dsgai",
          "catalog_version": "1.0",
          "id": "DSGAI14",
          "title_in_catalog": "Excessive Telemetry & Monitoring Leakage",
          "mapping_quality": "exact",
          "verified": true
        },
        {
          "catalog": "owasp-llm-top10",
          "catalog_version": "2025",
          "id": "LLM02:2025",
          "title_in_catalog": "Sensitive Information Disclosure",
          "mapping_quality": "closest",
          "verified": true
        }
      ],
      "paper_refs": [],
      "incident_refs": [
        {
          "type": "cve",
          "id": "CVE-2026-41947",
          "label": "Dify < 1.14.2 Authorization Bypass via Trace Configuration Endpoints",
          "verified": true
        }
      ],
      "srf_crosswalk": [
        "dsgai14"
      ],
      "related": [
        "atk-repudiation-log-tampering",
        "atk-cross-tenant-leakage"
      ],
      "origin": "seed",
      "status": "active",
      "merged_into": null,
      "verification": {
        "checked_on": "2026-10-01",
        "checked_by": "AI agent in Cursor, session of 2026-10-01",
        "reviewed_by": null,
        "methods": [
          "owasp-llm-pages",
          "dsgai-taxonomy-json",
          "cve-services-api",
          "crosswalk-lookup"
        ],
        "notes": "The seed row cited LLM02:2025 only. DSGAI14 Excessive Telemetry & Monitoring Leakage names this class. CVE-2026-41947 lets a user of one tenant set trace configuration on another tenant's application."
      },
      "added_in": "0.1.0",
      "last_changed_in": "0.1.0"
    },
    {
      "id": "atk-rag-poisoning",
      "name": "RAG and knowledge-base poisoning",
      "aliases": [
        "PoisonedRAG"
      ],
      "family": "poisoning",
      "scope": "ai",
      "topics": [],
      "failure_mode": "Planted documents rank high for target queries and steer answers or actions.",
      "taxonomy_refs": [
        {
          "catalog": "mitre-atlas",
          "catalog_version": "v2026.08",
          "id": "AML.T0070",
          "title_in_catalog": "RAG Poisoning",
          "mapping_quality": "exact",
          "verified": true
        },
        {
          "catalog": "mitre-atlas",
          "catalog_version": "v2026.08",
          "id": "AML.T0071",
          "title_in_catalog": "False RAG Entry Injection",
          "mapping_quality": "closest",
          "verified": true
        },
        {
          "catalog": "owasp-llm-top10",
          "catalog_version": "2025",
          "id": "LLM08:2025",
          "title_in_catalog": "Vector and Embedding Weaknesses",
          "mapping_quality": "closest",
          "verified": true
        },
        {
          "catalog": "owasp-dsgai",
          "catalog_version": "1.0",
          "id": "DSGAI21",
          "title_in_catalog": "Disinformation & Integrity Attacks via Data Poisoning",
          "mapping_quality": "exact",
          "verified": true
        }
      ],
      "paper_refs": [
        {
          "type": "arxiv",
          "id": "2402.07867",
          "title": "PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models",
          "first_author": "Zou",
          "year": 2024,
          "venue": null,
          "verified": true
        },
        {
          "type": "arxiv",
          "id": "2507.08862",
          "title": "RAG Safety: Exploring Knowledge Poisoning Attacks to Retrieval-Augmented Generation",
          "first_author": "Zhao",
          "year": 2025,
          "venue": null,
          "verified": true
        }
      ],
      "incident_refs": [],
      "srf_crosswalk": [
        "dsgai21"
      ],
      "related": [
        "atk-indirect-prompt-injection",
        "atk-agent-memory-poisoning"
      ],
      "origin": "seed",
      "status": "active",
      "merged_into": null,
      "verification": {
        "checked_on": "2026-10-01",
        "checked_by": "AI agent in Cursor, session of 2026-10-01",
        "reviewed_by": null,
        "methods": [
          "atlas-release-yaml",
          "atlas-next-release-diff",
          "owasp-llm-pages",
          "dsgai-taxonomy-json",
          "arxiv-api",
          "crosswalk-lookup"
        ],
        "notes": ""
      },
      "added_in": "0.1.0",
      "last_changed_in": "0.1.0"
    },
    {
      "id": "atk-agent-memory-poisoning",
      "name": "Agent memory poisoning",
      "aliases": [
        "MINJA",
        "AgentPoison"
      ],
      "family": "poisoning",
      "scope": "agentic",
      "topics": [],
      "failure_mode": "A memory item written from untrusted input shapes later sessions.",
      "taxonomy_refs": [
        {
          "catalog": "mitre-atlas",
          "catalog_version": "v2026.08",
          "id": "AML.T0080.000",
          "title_in_catalog": "AI Agent Context Poisoning: Memory",
          "mapping_quality": "exact",
          "verified": true
        },
        {
          "catalog": "owasp-agentic-threats",
          "catalog_version": "1.1",
          "id": "T1",
          "title_in_catalog": "Memory Poisoning",
          "mapping_quality": "exact",
          "verified": true
        }
      ],
      "paper_refs": [
        {
          "type": "arxiv",
          "id": "2503.03704",
          "title": "Memory Injection Attacks on LLM Agents via Query-Only Interaction",
          "first_author": "Dong",
          "year": 2025,
          "venue": null,
          "verified": true
        },
        {
          "type": "arxiv",
          "id": "2407.12784",
          "title": "AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases",
          "first_author": "Chen",
          "year": 2024,
          "venue": null,
          "verified": true
        }
      ],
      "incident_refs": [
        {
          "type": "atlas-case-study",
          "id": "AML.CS0040",
          "label": "Hacking ChatGPT's Memories with Prompt Injection",
          "catalog_version": "v2026.08",
          "verified": true
        }
      ],
      "srf_crosswalk": [],
      "related": [
        "atk-rag-poisoning",
        "atk-indirect-prompt-injection"
      ],
      "origin": "seed",
      "status": "active",
      "merged_into": null,
      "verification": {
        "checked_on": "2026-10-01",
        "checked_by": "AI agent in Cursor, session of 2026-10-01",
        "reviewed_by": null,
        "methods": [
          "atlas-release-yaml",
          "atlas-next-release-diff",
          "owasp-agentic-pdf",
          "arxiv-api"
        ],
        "notes": "The seed row reached MINJA and AgentPoison through the CoSAI incident-response document. Both arXiv ids are now pinned directly."
      },
      "added_in": "0.1.0",
      "last_changed_in": "0.1.0"
    },
    {
      "id": "atk-training-data-poisoning",
      "name": "Training-data poisoning",
      "aliases": [],
      "family": "poisoning",
      "scope": "ai",
      "topics": [
        "supply-chain"
      ],
      "failure_mode": "Poisoned training or fine-tuning data plants behavior that no runtime field sees enter.",
      "taxonomy_refs": [
        {
          "catalog": "mitre-atlas",
          "catalog_version": "v2026.08",
          "id": "AML.T0020",
          "title_in_catalog": "Training Data Poisoning",
          "mapping_quality": "exact",
          "verified": true
        },
        {
          "catalog": "owasp-llm-top10",
          "catalog_version": "2025",
          "id": "LLM04:2025",
          "title_in_catalog": "Data and Model Poisoning",
          "mapping_quality": "exact",
          "verified": true
        },
        {
          "catalog": "owasp-dsgai",
          "catalog_version": "1.0",
          "id": "DSGAI04",
          "title_in_catalog": "Data, Model & Artifact Poisoning",
          "mapping_quality": "exact",
          "verified": true
        }
      ],
      "paper_refs": [
        {
          "type": "arxiv",
          "id": "2302.10149",
          "title": "Poisoning Web-Scale Training Datasets is Practical",
          "first_author": "Carlini",
          "year": 2023,
          "venue": null,
          "verified": true
        }
      ],
      "incident_refs": [],
      "srf_crosswalk": [
        "datapoison"
      ],
      "related": [
        "atk-backdoored-model-trigger"
      ],
      "origin": "seed",
      "status": "active",
      "merged_into": null,
      "verification": {
        "checked_on": "2026-10-01",
        "checked_by": "AI agent in Cursor, session of 2026-10-01",
        "reviewed_by": null,
        "methods": [
          "atlas-release-yaml",
          "atlas-next-release-diff",
          "owasp-llm-pages",
          "dsgai-taxonomy-json",
          "arxiv-api",
          "crosswalk-lookup"
        ],
        "notes": ""
      },
      "added_in": "0.1.0",
      "last_changed_in": "0.1.0"
    },
    {
      "id": "atk-backdoored-model-trigger",
      "name": "Backdoored model with trigger behavior",
      "aliases": [
        "sleeper agent"
      ],
      "family": "supply chain",
      "scope": "ai",
      "topics": [
        "supply-chain",
        "model-signing"
      ],
      "failure_mode": "A model behaves normally until a trigger appears, then acts against the deployer.",
      "taxonomy_refs": [
        {
          "catalog": "mitre-atlas",
          "catalog_version": "v2026.08",
          "id": "AML.T0018.000",
          "title_in_catalog": "Manipulate AI Model: Poison AI Model",
          "mapping_quality": "exact",
          "verified": true
        },
        {
          "catalog": "mitre-atlas",
          "catalog_version": "v2026.08",
          "id": "AML.T0043.004",
          "title_in_catalog": "Craft Adversarial Data: Insert Backdoor Trigger",
          "mapping_quality": "exact",
          "verified": true
        },
        {
          "catalog": "owasp-llm-top10",
          "catalog_version": "2025",
          "id": "LLM04:2025",
          "title_in_catalog": "Data and Model Poisoning",
          "mapping_quality": "closest",
          "verified": true
        }
      ],
      "paper_refs": [
        {
          "type": "arxiv",
          "id": "2401.05566",
          "title": "Sleeper Agents: Training Deceptive LLMs that Persist Through Safety Training",
          "first_author": "Hubinger",
          "year": 2024,
          "venue": null,
          "verified": true
        }
      ],
      "incident_refs": [],
      "srf_crosswalk": [
        "devmodelpoison",
        "supplymodelpoison"
      ],
      "related": [
        "atk-training-data-poisoning",
        "atk-malicious-model-artifact"
      ],
      "origin": "seed",
      "status": "active",
      "merged_into": null,
      "verification": {
        "checked_on": "2026-10-01",
        "checked_by": "AI agent in Cursor, session of 2026-10-01",
        "reviewed_by": null,
        "methods": [
          "atlas-release-yaml",
          "atlas-next-release-diff",
          "owasp-llm-pages",
          "arxiv-api",
          "crosswalk-lookup"
        ],
        "notes": "The seed row cited AML.T0018, which ATLAS v2026.08 titles Manipulate AI Model. Sub-technique .000 Poison AI Model is the narrower fit."
      },
      "added_in": "0.1.0",
      "last_changed_in": "0.1.0"
    },
    {
      "id": "atk-malicious-model-artifact",
      "name": "Malicious model artifact",
      "aliases": [],
      "family": "supply chain",
      "scope": "ai",
      "topics": [
        "supply-chain",
        "model-signing"
      ],
      "failure_mode": "A tampered model file from a hub or registry carries attacker behavior into serving.",
      "taxonomy_refs": [
        {
          "catalog": "mitre-atlas",
          "catalog_version": "v2026.08",
          "id": "AML.T0010.003",
          "title_in_catalog": "AI Supply Chain Compromise: Model",
          "mapping_quality": "exact",
          "verified": true
        },
        {
          "catalog": "mitre-atlas",
          "catalog_version": "v2026.08",
          "id": "AML.T0018.002",
          "title_in_catalog": "Manipulate AI Model: Embed Malware",
          "mapping_quality": "exact",
          "verified": true
        },
        {
          "catalog": "mitre-atlas",
          "catalog_version": "v2026.08",
          "id": "AML.T0011.000",
          "title_in_catalog": "User Execution: Unsafe AI Artifacts",
          "mapping_quality": "closest",
          "verified": true
        },
        {
          "catalog": "owasp-llm-top10",
          "catalog_version": "2025",
          "id": "LLM03:2025",
          "title_in_catalog": "Supply Chain",
          "mapping_quality": "exact",
          "verified": true
        },
        {
          "catalog": "cwe",
          "catalog_version": "4.20",
          "id": "CWE-502",
          "title_in_catalog": "Deserialization of Untrusted Data",
          "mapping_quality": "closest",
          "verified": true
        }
      ],
      "paper_refs": [],
      "incident_refs": [],
      "srf_crosswalk": [
        "supplymodelpoison"
      ],
      "related": [
        "atk-backdoored-model-trigger",
        "atk-mcp-tool-poisoning"
      ],
      "origin": "seed",
      "status": "active",
      "merged_into": null,
      "verification": {
        "checked_on": "2026-10-01",
        "checked_by": "AI agent in Cursor, session of 2026-10-01",
        "reviewed_by": null,
        "methods": [
          "atlas-release-yaml",
          "atlas-next-release-diff",
          "owasp-llm-pages",
          "cwe-api",
          "crosswalk-lookup"
        ],
        "notes": "The seed row cited the parent AML.T0010. CWE-502 is the classical weakness behind unsafe serialized model formats."
      },
      "added_in": "0.1.0",
      "last_changed_in": "0.1.0"
    },
    {
      "id": "atk-mcp-tool-poisoning",
      "name": "MCP tool poisoning and post-approval definition change",
      "aliases": [
        "tool description injection",
        "rug pull"
      ],
      "family": "tool supply chain",
      "scope": "agentic",
      "topics": [
        "MCP",
        "tool-calling",
        "supply-chain"
      ],
      "failure_mode": "A tool description carries instructions, or changes after approval, and the agent follows it.",
      "taxonomy_refs": [
        {
          "catalog": "mitre-atlas",
          "catalog_version": "v2026.08",
          "id": "AML.T0110.000",
          "title_in_catalog": "AI Agent Tool Poisoning: Definition and Instructions",
          "mapping_quality": "exact",
          "verified": true
        },
        {
          "catalog": "mitre-atlas",
          "catalog_version": "v2026.08",
          "id": "AML.T0109",
          "title_in_catalog": "AI Supply Chain Rug Pull",
          "mapping_quality": "exact",
          "verified": true
        },
        {
          "catalog": "owasp-agentic-threats",
          "catalog_version": "1.1",
          "id": "T16",
          "title_in_catalog": "Insecure Inter-Agent Protocol Abuse",
          "mapping_quality": "closest",
          "verified": true
        }
      ],
      "paper_refs": [],
      "incident_refs": [
        {
          "type": "atlas-case-study",
          "id": "AML.CS0054",
          "label": "Data Exfiltration via Remote Poisoned MCP Tool",
          "catalog_version": "v2026.08",
          "verified": true
        },
        {
          "type": "atlas-case-study",
          "id": "AML.CS0053",
          "label": "Poisoned Postmark MCP Server Email Exfiltration",
          "catalog_version": "v2026.08",
          "verified": true
        },
        {
          "type": "cve",
          "id": "CVE-2025-54136",
          "label": "Cursor's Modification of MCP Server Definitions Bypasses Manual Re-approvals",
          "verified": true
        },
        {
          "type": "url",
          "id": "https://invariantlabs.ai/blog/mcp-security-notification-tool-poisoning-attacks",
          "label": "Invariant Labs, MCP tool poisoning notification, April 2025",
          "url": "https://invariantlabs.ai/blog/mcp-security-notification-tool-poisoning-attacks",
          "accessed": "2026-10-01",
          "verified": true
        }
      ],
      "srf_crosswalk": [
        "dsgai06"
      ],
      "related": [
        "atk-malicious-model-artifact",
        "atk-indirect-prompt-injection",
        "atk-confused-deputy-delegation"
      ],
      "origin": "seed",
      "status": "active",
      "merged_into": null,
      "verification": {
        "checked_on": "2026-10-01",
        "checked_by": "AI agent in Cursor, session of 2026-10-01",
        "reviewed_by": null,
        "methods": [
          "atlas-release-yaml",
          "atlas-next-release-diff",
          "owasp-agentic-pdf",
          "cve-services-api",
          "url-fetch",
          "crosswalk-lookup"
        ],
        "notes": "The seed row cited AML.T0051.001 and an Invariant Labs post with no stable id. ATLAS case study AML.CS0054 cites that post and gives it a stable id. AML.T0109 and CVE-2025-54136 cover the post-approval change."
      },
      "added_in": "0.1.0",
      "last_changed_in": "0.1.0"
    },
    {
      "id": "atk-hallucinated-package-squatting",
      "name": "Hallucinated package names",
      "aliases": [
        "package hallucination"
      ],
      "family": "supply chain",
      "scope": "ai",
      "topics": [
        "supply-chain"
      ],
      "failure_mode": "An agent installs a model-invented package name that a third party has registered.",
      "taxonomy_refs": [
        {
          "catalog": "mitre-atlas",
          "catalog_version": "v2026.08",
          "id": "AML.T0060",
          "title_in_catalog": "Publish Hallucinated Entities",
          "mapping_quality": "exact",
          "verified": true
        },
        {
          "catalog": "mitre-atlas",
          "catalog_version": "v2026.08",
          "id": "AML.T0062",
          "title_in_catalog": "Discover LLM Hallucinations",
          "mapping_quality": "closest",
          "verified": true
        },
        {
          "catalog": "owasp-llm-top10",
          "catalog_version": "2025",
          "id": "LLM09:2025",
          "title_in_catalog": "Misinformation",
          "mapping_quality": "exact",
          "verified": true
        }
      ],
      "paper_refs": [
        {
          "type": "arxiv",
          "id": "2406.10279",
          "title": "We Have a Package for You! A Comprehensive Analysis of Package Hallucinations by Code Generating LLMs",
          "first_author": "Spracklen",
          "year": 2024,
          "venue": null,
          "verified": true
        }
      ],
      "incident_refs": [],
      "srf_crosswalk": [],
      "related": [
        "atk-malicious-model-artifact"
      ],
      "origin": "seed",
      "status": "active",
      "merged_into": null,
      "verification": {
        "checked_on": "2026-10-01",
        "checked_by": "AI agent in Cursor, session of 2026-10-01",
        "reviewed_by": null,
        "methods": [
          "atlas-release-yaml",
          "atlas-next-release-diff",
          "owasp-llm-pages",
          "arxiv-api"
        ],
        "notes": "LLM09:2025 Scenario 1 describes this class."
      },
      "added_in": "0.1.0",
      "last_changed_in": "0.1.0"
    },
    {
      "id": "atk-excessive-agency",
      "name": "Excessive agency",
      "aliases": [],
      "family": "tool calling",
      "scope": "agentic",
      "topics": [
        "tool-calling"
      ],
      "failure_mode": "An agent holds more tools or permissions than its task needs, so one bad decision has high impact.",
      "taxonomy_refs": [
        {
          "catalog": "owasp-llm-top10",
          "catalog_version": "2025",
          "id": "LLM06:2025",
          "title_in_catalog": "Excessive Agency",
          "mapping_quality": "exact",
          "verified": true
        },
        {
          "catalog": "owasp-agentic-threats",
          "catalog_version": "1.1",
          "id": "T2",
          "title_in_catalog": "Tool Misuse",
          "mapping_quality": "closest",
          "verified": true
        },
        {
          "catalog": "mitre-atlas",
          "catalog_version": "v2026.08",
          "id": "AML.T0053",
          "title_in_catalog": "AI Agent Tool Invocation",
          "mapping_quality": "closest",
          "verified": true
        }
      ],
      "paper_refs": [],
      "incident_refs": [],
      "srf_crosswalk": [
        "dsgai06"
      ],
      "related": [
        "atk-confused-deputy-delegation",
        "atk-sandbox-escape"
      ],
      "origin": "seed",
      "status": "active",
      "merged_into": null,
      "verification": {
        "checked_on": "2026-10-01",
        "checked_by": "AI agent in Cursor, session of 2026-10-01",
        "reviewed_by": null,
        "methods": [
          "atlas-release-yaml",
          "atlas-next-release-diff",
          "owasp-llm-pages",
          "owasp-agentic-pdf",
          "crosswalk-lookup"
        ],
        "notes": ""
      },
      "added_in": "0.1.0",
      "last_changed_in": "0.1.0"
    },
    {
      "id": "atk-confused-deputy-delegation",
      "name": "Confused deputy and delegated-authority escalation",
      "aliases": [],
      "family": "identity",
      "scope": "agentic",
      "topics": [
        "agent-identity",
        "tool-calling",
        "MCP"
      ],
      "failure_mode": "A downstream hop acts with broader authority than the delegating party granted.",
      "taxonomy_refs": [
        {
          "catalog": "owasp-agentic-threats",
          "catalog_version": "1.1",
          "id": "T3",
          "title_in_catalog": "Privilege Compromise",
          "mapping_quality": "exact",
          "verified": true
        },
        {
          "catalog": "owasp-agentic-threats",
          "catalog_version": "1.1",
          "id": "T14",
          "title_in_catalog": "Human Attacks on Multi-Agent Systems",
          "mapping_quality": "closest",
          "verified": true
        },
        {
          "catalog": "cwe",
          "catalog_version": "4.20",
          "id": "CWE-441",
          "title_in_catalog": "Unintended Proxy or Intermediary ('Confused Deputy')",
          "mapping_quality": "exact",
          "verified": true
        },
        {
          "catalog": "mitre-atlas",
          "catalog_version": "v2026.08",
          "id": "AML.T0053",
          "title_in_catalog": "AI Agent Tool Invocation",
          "mapping_quality": "closest",
          "verified": true
        }
      ],
      "paper_refs": [],
      "incident_refs": [
        {
          "type": "cve",
          "id": "CVE-2025-5071",
          "label": "AI Engine 2.8.0 - 2.8.3 - Authenticated (Subscriber+) Insufficient Authorization to Privilege Escalation via MCP",
          "verified": true
        }
      ],
      "srf_crosswalk": [
        "dsgai02"
      ],
      "related": [
        "atk-excessive-agency",
        "atk-display-name-identity-spoofing",
        "atk-agent-config-credential-exposure"
      ],
      "origin": "seed",
      "status": "active",
      "merged_into": null,
      "verification": {
        "checked_on": "2026-10-01",
        "checked_by": "AI agent in Cursor, session of 2026-10-01",
        "reviewed_by": null,
        "methods": [
          "atlas-release-yaml",
          "atlas-next-release-diff",
          "owasp-agentic-pdf",
          "cwe-api",
          "cve-services-api",
          "crosswalk-lookup"
        ],
        "notes": "CWE-441 is the classical name for this class."
      },
      "added_in": "0.1.0",
      "last_changed_in": "0.1.0"
    },
    {
      "id": "atk-display-name-identity-spoofing",
      "name": "Identity spoofing through display names",
      "aliases": [],
      "family": "identity",
      "scope": "agentic",
      "topics": [
        "agent-identity"
      ],
      "failure_mode": "A spoofable display name, not a verified identifier, authorizes an action.",
      "taxonomy_refs": [
        {
          "catalog": "owasp-agentic-threats",
          "catalog_version": "1.1",
          "id": "T9",
          "title_in_catalog": "Identity Spoofing & Impersonation",
          "mapping_quality": "exact",
          "verified": true
        },
        {
          "catalog": "mitre-atlas",
          "catalog_version": "v2026.08",
          "id": "AML.T0073",
          "title_in_catalog": "Impersonation",
          "mapping_quality": "closest",
          "verified": true
        }
      ],
      "paper_refs": [
        {
          "type": "arxiv",
          "id": "2602.20021",
          "title": "Agents of Chaos",
          "first_author": "Shapira",
          "year": 2026,
          "venue": null,
          "verified": true
        }
      ],
      "incident_refs": [],
      "srf_crosswalk": [
        "dsgai02"
      ],
      "related": [
        "atk-confused-deputy-delegation"
      ],
      "origin": "seed",
      "status": "active",
      "merged_into": null,
      "verification": {
        "checked_on": "2026-10-01",
        "checked_by": "AI agent in Cursor, session of 2026-10-01",
        "reviewed_by": null,
        "methods": [
          "atlas-release-yaml",
          "atlas-next-release-diff",
          "owasp-agentic-pdf",
          "arxiv-api",
          "crosswalk-lookup"
        ],
        "notes": "Agents of Chaos is cited for its owner identity spoofing case (AOC-08 in the RFC). The arXiv id, title, and first author were checked; the case text was not reread."
      },
      "added_in": "0.1.0",
      "last_changed_in": "0.1.0"
    },
    {
      "id": "atk-sandbox-escape",
      "name": "Sandbox or test-environment escape",
      "aliases": [],
      "family": "isolation",
      "scope": "agentic",
      "topics": [
        "tool-calling"
      ],
      "failure_mode": "An agent's actions reach systems outside its intended isolation boundary.",
      "taxonomy_refs": [
        {
          "catalog": "mitre-atlas",
          "catalog_version": "v2026.08",
          "id": "AML.T0105",
          "title_in_catalog": "Escape to Host",
          "mapping_quality": "exact",
          "verified": true
        },
        {
          "catalog": "owasp-agentic-threats",
          "catalog_version": "1.1",
          "id": "T11",
          "title_in_catalog": "Unexpected RCE and Code Attacks",
          "mapping_quality": "closest",
          "verified": true
        }
      ],
      "paper_refs": [],
      "incident_refs": [
        {
          "type": "cve",
          "id": "CVE-2026-25253",
          "label": "OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically mak",
          "verified": true
        },
        {
          "type": "atlas-case-study",
          "id": "AML.CS0050",
          "label": "OpenClaw 1-Click Remote Code Execution",
          "catalog_version": "v2026.08",
          "verified": true
        }
      ],
      "srf_crosswalk": [],
      "related": [
        "atk-excessive-agency",
        "atk-llm-output-os-command-injection"
      ],
      "origin": "seed",
      "status": "active",
      "merged_into": null,
      "verification": {
        "checked_on": "2026-10-01",
        "checked_by": "AI agent in Cursor, session of 2026-10-01",
        "reviewed_by": null,
        "methods": [
          "atlas-release-yaml",
          "atlas-next-release-diff",
          "owasp-agentic-pdf",
          "cve-services-api"
        ],
        "notes": "The seed row used OWASP Agentic T11 as the closest match. ATLAS v2026.08 defines AML.T0105 Escape to Host for this class, and AML.CS0050 employs it."
      },
      "added_in": "0.1.0",
      "last_changed_in": "0.1.0"
    },
    {
      "id": "atk-self-replicating-prompt",
      "name": "Self-replicating prompt across agents",
      "aliases": [
        "AI worm",
        "Morris II"
      ],
      "family": "multi-agent",
      "scope": "agentic",
      "topics": [],
      "failure_mode": "An injected instruction copies itself into output that other assistants consume.",
      "taxonomy_refs": [
        {
          "catalog": "mitre-atlas",
          "catalog_version": "v2026.08",
          "id": "AML.T0061",
          "title_in_catalog": "LLM Prompt Self-Replication",
          "mapping_quality": "exact",
          "verified": true
        },
        {
          "catalog": "owasp-agentic-threats",
          "catalog_version": "1.1",
          "id": "T12",
          "title_in_catalog": "Agent Communication Poisoning",
          "mapping_quality": "closest",
          "verified": true
        }
      ],
      "paper_refs": [
        {
          "type": "arxiv",
          "id": "2403.02817",
          "title": "Here Comes The AI Worm: Unleashing Zero-click Worms that Target GenAI-Powered Applications",
          "first_author": "Cohen",
          "year": 2024,
          "venue": null,
          "verified": true
        }
      ],
      "incident_refs": [
        {
          "type": "atlas-case-study",
          "id": "AML.CS0024",
          "label": "Morris II Worm: RAG-Based Attack",
          "catalog_version": "v2026.08",
          "verified": true
        }
      ],
      "srf_crosswalk": [
        "indirectpromptinjection"
      ],
      "related": [
        "atk-indirect-prompt-injection",
        "atk-rag-poisoning"
      ],
      "origin": "seed",
      "status": "active",
      "merged_into": null,
      "verification": {
        "checked_on": "2026-10-01",
        "checked_by": "AI agent in Cursor, session of 2026-10-01",
        "reviewed_by": null,
        "methods": [
          "atlas-release-yaml",
          "atlas-next-release-diff",
          "owasp-agentic-pdf",
          "arxiv-api",
          "crosswalk-lookup"
        ],
        "notes": ""
      },
      "added_in": "0.1.0",
      "last_changed_in": "0.1.0"
    },
    {
      "id": "atk-unbounded-consumption",
      "name": "Unbounded consumption and runaway loops",
      "aliases": [],
      "family": "resource abuse",
      "scope": "agentic",
      "topics": [
        "tool-calling"
      ],
      "failure_mode": "Loops or crafted input consume tokens, compute, or spend past any budget.",
      "taxonomy_refs": [
        {
          "catalog": "owasp-llm-top10",
          "catalog_version": "2025",
          "id": "LLM10:2025",
          "title_in_catalog": "Unbounded Consumption",
          "mapping_quality": "exact",
          "verified": true
        },
        {
          "catalog": "mitre-atlas",
          "catalog_version": "v2026.08",
          "id": "AML.T0034.002",
          "title_in_catalog": "Cost Harvesting: Agentic Resource Consumption",
          "mapping_quality": "exact",
          "verified": true
        },
        {
          "catalog": "mitre-atlas",
          "catalog_version": "v2026.08",
          "id": "AML.T0029",
          "title_in_catalog": "Denial of AI Service",
          "mapping_quality": "closest",
          "verified": true
        },
        {
          "catalog": "owasp-agentic-threats",
          "catalog_version": "1.1",
          "id": "T4",
          "title_in_catalog": "Resource Overload",
          "mapping_quality": "exact",
          "verified": true
        }
      ],
      "paper_refs": [],
      "incident_refs": [],
      "srf_crosswalk": [
        "airesourceexhaustion"
      ],
      "related": [],
      "origin": "seed",
      "status": "active",
      "merged_into": null,
      "verification": {
        "checked_on": "2026-10-01",
        "checked_by": "AI agent in Cursor, session of 2026-10-01",
        "reviewed_by": null,
        "methods": [
          "atlas-release-yaml",
          "atlas-next-release-diff",
          "owasp-llm-pages",
          "owasp-agentic-pdf",
          "crosswalk-lookup"
        ],
        "notes": "The seed row cited the parent AML.T0034. Sub-technique .002 Agentic Resource Consumption is the narrower fit."
      },
      "added_in": "0.1.0",
      "last_changed_in": "0.1.0"
    },
    {
      "id": "atk-deceptive-agent-self-report",
      "name": "Deceptive agent self-report",
      "aliases": [],
      "family": "integrity",
      "scope": "agentic",
      "topics": [
        "telemetry",
        "oversight-tiers"
      ],
      "failure_mode": "An agent reports an outcome that did not happen, and a detection trusts the report.",
      "taxonomy_refs": [
        {
          "catalog": "owasp-agentic-threats",
          "catalog_version": "1.1",
          "id": "T7",
          "title_in_catalog": "Misaligned & Deceptive Behaviors",
          "mapping_quality": "closest",
          "verified": true
        }
      ],
      "paper_refs": [
        {
          "type": "arxiv",
          "id": "2602.20021",
          "title": "Agents of Chaos",
          "first_author": "Shapira",
          "year": 2026,
          "venue": null,
          "verified": true
        }
      ],
      "incident_refs": [],
      "srf_crosswalk": [],
      "related": [
        "atk-repudiation-log-tampering",
        "atk-observability-plane-evasion"
      ],
      "origin": "seed",
      "status": "active",
      "merged_into": null,
      "verification": {
        "checked_on": "2026-10-01",
        "checked_by": "AI agent in Cursor, session of 2026-10-01",
        "reviewed_by": null,
        "methods": [
          "owasp-agentic-pdf",
          "arxiv-api"
        ],
        "notes": "No ATLAS v2026.08 technique describes a false outcome report. The RFC appendix A.5 tag for AOC-01, AML.T0031 Erode AI Model Integrity, describes performance degradation and is not cited here. Agents of Chaos is cited for its AOC-01 case; the case text was not reread."
      },
      "added_in": "0.1.0",
      "last_changed_in": "0.1.0"
    },
    {
      "id": "atk-repudiation-log-tampering",
      "name": "Repudiation and log tampering",
      "aliases": [],
      "family": "telemetry plane",
      "scope": "agentic",
      "topics": [
        "telemetry"
      ],
      "failure_mode": "Records are removed, reordered, or altered, so an action cannot be traced to its actor.",
      "taxonomy_refs": [
        {
          "catalog": "owasp-agentic-threats",
          "catalog_version": "1.1",
          "id": "T8",
          "title_in_catalog": "Repudiation & Untraceability",
          "mapping_quality": "exact",
          "verified": true
        },
        {
          "catalog": "mitre-atlas",
          "catalog_version": "v2026.08",
          "id": "AML.T0092",
          "title_in_catalog": "Manipulate User LLM Chat History",
          "mapping_quality": "closest",
          "verified": true
        }
      ],
      "paper_refs": [],
      "incident_refs": [],
      "srf_crosswalk": [],
      "related": [
        "atk-telemetry-store-disclosure",
        "atk-observability-plane-evasion"
      ],
      "origin": "seed",
      "status": "active",
      "merged_into": null,
      "verification": {
        "checked_on": "2026-10-01",
        "checked_by": "AI agent in Cursor, session of 2026-10-01",
        "reviewed_by": null,
        "methods": [
          "atlas-release-yaml",
          "atlas-next-release-diff",
          "owasp-agentic-pdf"
        ],
        "notes": ""
      },
      "added_in": "0.1.0",
      "last_changed_in": "0.1.0"
    },
    {
      "id": "atk-observability-plane-evasion",
      "name": "Observability-plane evasion",
      "aliases": [],
      "family": "telemetry plane",
      "scope": "agentic",
      "topics": [
        "telemetry"
      ],
      "failure_mode": "A starved guardrail or disabled hook produces silence that reads as allow.",
      "taxonomy_refs": [
        {
          "catalog": "mitre-atlas",
          "catalog_version": "v2026.08",
          "id": "AML.T0081",
          "title_in_catalog": "Modify AI Agent Configuration",
          "mapping_quality": "closest",
          "verified": true
        },
        {
          "catalog": "owasp-agentic-threats",
          "catalog_version": "1.1",
          "id": "T8",
          "title_in_catalog": "Repudiation & Untraceability",
          "mapping_quality": "closest",
          "verified": true
        }
      ],
      "paper_refs": [],
      "incident_refs": [],
      "srf_crosswalk": [],
      "related": [
        "atk-repudiation-log-tampering",
        "atk-deceptive-agent-self-report"
      ],
      "origin": "seed",
      "status": "active",
      "merged_into": null,
      "verification": {
        "checked_on": "2026-10-01",
        "checked_by": "AI agent in Cursor, session of 2026-10-01",
        "reviewed_by": null,
        "methods": [
          "atlas-release-yaml",
          "atlas-next-release-diff",
          "owasp-agentic-pdf"
        ],
        "notes": "No paper or catalog entry found that names a starved guardrail or disabled hook whose silence a detection reads as allow. The class comes from the CoSAI AI Telemetry RFC v0.6 draft. AML.T0081 covers the disabled-setting half only."
      },
      "added_in": "0.1.0",
      "last_changed_in": "0.1.0"
    },
    {
      "id": "atk-telemetry-borne-injection-into-llm-triage",
      "name": "Injection carried by telemetry into LLM-assisted triage",
      "aliases": [
        "log-substrate prompt injection",
        "passive prompt injection"
      ],
      "family": "telemetry plane",
      "scope": "ai",
      "topics": [
        "telemetry"
      ],
      "failure_mode": "Attacker text captured in model input or tool call fields instructs an LLM-based analyst tool that reads the telemetry.",
      "taxonomy_refs": [
        {
          "catalog": "mitre-atlas",
          "catalog_version": "v2026.08",
          "id": "AML.T0051.001",
          "title_in_catalog": "LLM Prompt Injection: Indirect",
          "mapping_quality": "exact",
          "verified": true
        }
      ],
      "paper_refs": [
        {
          "type": "arxiv",
          "id": "2605.24421",
          "title": "Poisoning the Watchtower: Prompt Injection Attacks Against LLM-Augmented Security Operations Through Adversarial Log Content",
          "first_author": "Pandey",
          "year": 2026,
          "venue": null,
          "verified": true
        },
        {
          "type": "arxiv",
          "id": "2607.14493",
          "title": "Context Contamination in LLM Analysis of Network Security Logs: Poison with Passive Prompt Injection and Mitigation Evaluation",
          "first_author": "Karanjai",
          "year": 2026,
          "venue": null,
          "verified": true
        },
        {
          "type": "arxiv",
          "id": "2607.24174",
          "title": "Just Testing, Move Along: Evasion of LLM-based System Log Interpretation by Prompt Injection",
          "first_author": "Landauer",
          "year": 2026,
          "venue": null,
          "verified": true
        }
      ],
      "incident_refs": [],
      "srf_crosswalk": [
        "indirectpromptinjection"
      ],
      "related": [
        "atk-indirect-prompt-injection",
        "atk-telemetry-store-disclosure"
      ],
      "origin": "seed",
      "status": "active",
      "merged_into": null,
      "verification": {
        "checked_on": "2026-10-01",
        "checked_by": "AI agent in Cursor, session of 2026-10-01",
        "reviewed_by": null,
        "methods": [
          "atlas-release-yaml",
          "atlas-next-release-diff",
          "arxiv-api",
          "crosswalk-lookup"
        ],
        "notes": "The seed row mapped this class by analogy with no paper. Three 2026 arXiv papers show log fields acting as attacker-controlled content that an LLM triage tool reads, which is the data-channel case AML.T0051.001 covers; their abstracts were read on the check date."
      },
      "added_in": "0.1.0",
      "last_changed_in": "0.1.0"
    },
    {
      "id": "atk-approval-fatigue",
      "name": "Approval fatigue",
      "aliases": [],
      "family": "oversight",
      "scope": "agentic",
      "topics": [
        "oversight-tiers"
      ],
      "failure_mode": "A flood of approval requests leads a human approver to accept a harmful one.",
      "taxonomy_refs": [
        {
          "catalog": "owasp-agentic-threats",
          "catalog_version": "1.1",
          "id": "T10",
          "title_in_catalog": "Overwhelming Human in the Loop",
          "mapping_quality": "exact",
          "verified": true
        }
      ],
      "paper_refs": [],
      "incident_refs": [],
      "srf_crosswalk": [],
      "related": [
        "atk-deceptive-agent-self-report"
      ],
      "origin": "seed",
      "status": "active",
      "merged_into": null,
      "verification": {
        "checked_on": "2026-10-01",
        "checked_by": "AI agent in Cursor, session of 2026-10-01",
        "reviewed_by": null,
        "methods": [
          "owasp-agentic-pdf"
        ],
        "notes": "No ATLAS v2026.08 technique describes overloading a human approver."
      },
      "added_in": "0.1.0",
      "last_changed_in": "0.1.0"
    },
    {
      "id": "atk-model-extraction-via-api",
      "name": "Model extraction through the inference API",
      "aliases": [],
      "family": "extraction",
      "scope": "ai",
      "topics": [],
      "failure_mode": "High-volume queries recover model parameters or behavior the provider meant to keep private.",
      "taxonomy_refs": [
        {
          "catalog": "mitre-atlas",
          "catalog_version": "v2026.08",
          "id": "AML.T0024.002",
          "title_in_catalog": "Exfiltration via AI Inference API: Extract AI Model",
          "mapping_quality": "exact",
          "verified": true
        },
        {
          "catalog": "mitre-atlas",
          "catalog_version": "v2026.08",
          "id": "AML.T0005.001",
          "title_in_catalog": "Create Proxy AI Model: Train Proxy via Replication",
          "mapping_quality": "closest",
          "verified": true
        },
        {
          "catalog": "owasp-dsgai",
          "catalog_version": "1.0",
          "id": "DSGAI20",
          "title_in_catalog": "Model Exfiltration & IP Replication",
          "mapping_quality": "exact",
          "verified": true
        },
        {
          "catalog": "owasp-llm-top10",
          "catalog_version": "2025",
          "id": "LLM10:2025",
          "title_in_catalog": "Unbounded Consumption",
          "mapping_quality": "closest",
          "verified": true
        }
      ],
      "paper_refs": [
        {
          "type": "arxiv",
          "id": "2403.06634",
          "title": "Stealing Part of a Production Language Model",
          "first_author": "Carlini",
          "year": 2024,
          "venue": null,
          "verified": true
        }
      ],
      "incident_refs": [],
      "srf_crosswalk": [
        "modelexfiltration"
      ],
      "related": [
        "atk-training-data-extraction"
      ],
      "origin": "seed",
      "status": "active",
      "merged_into": null,
      "verification": {
        "checked_on": "2026-10-01",
        "checked_by": "AI agent in Cursor, session of 2026-10-01",
        "reviewed_by": null,
        "methods": [
          "atlas-release-yaml",
          "atlas-next-release-diff",
          "owasp-llm-pages",
          "dsgai-taxonomy-json",
          "arxiv-api",
          "crosswalk-lookup"
        ],
        "notes": "LLM10:2025 lists Model Extraction via API under unbounded consumption."
      },
      "added_in": "0.1.0",
      "last_changed_in": "0.1.0"
    },
    {
      "id": "atk-embedding-inversion",
      "name": "Embedding inversion",
      "aliases": [],
      "family": "disclosure",
      "scope": "ai",
      "topics": [],
      "failure_mode": "Stored embeddings are inverted to recover the source text.",
      "taxonomy_refs": [
        {
          "catalog": "owasp-llm-top10",
          "catalog_version": "2025",
          "id": "LLM08:2025",
          "title_in_catalog": "Vector and Embedding Weaknesses",
          "mapping_quality": "exact",
          "verified": true
        },
        {
          "catalog": "owasp-dsgai",
          "catalog_version": "1.0",
          "id": "DSGAI13",
          "title_in_catalog": "Vector Store Platform Data Security",
          "mapping_quality": "exact",
          "verified": true
        },
        {
          "catalog": "owasp-dsgai",
          "catalog_version": "1.0",
          "id": "DSGAI18",
          "title_in_catalog": "Inference & Data Reconstruction",
          "mapping_quality": "exact",
          "verified": true
        },
        {
          "catalog": "mitre-atlas",
          "catalog_version": "v2026.08",
          "id": "AML.T0024.001",
          "title_in_catalog": "Exfiltration via AI Inference API: Invert AI Model",
          "mapping_quality": "analogy",
          "verified": true
        }
      ],
      "paper_refs": [
        {
          "type": "arxiv",
          "id": "2310.06816",
          "title": "Text Embeddings Reveal (Almost) As Much As Text",
          "first_author": "Morris",
          "year": 2023,
          "venue": null,
          "verified": true
        }
      ],
      "incident_refs": [],
      "srf_crosswalk": [
        "dsgai13",
        "modelinversionandmembership"
      ],
      "related": [
        "atk-cross-tenant-leakage"
      ],
      "origin": "seed",
      "status": "active",
      "merged_into": null,
      "verification": {
        "checked_on": "2026-10-01",
        "checked_by": "AI agent in Cursor, session of 2026-10-01",
        "reviewed_by": null,
        "methods": [
          "atlas-release-yaml",
          "atlas-next-release-diff",
          "owasp-llm-pages",
          "dsgai-taxonomy-json",
          "arxiv-api",
          "crosswalk-lookup"
        ],
        "notes": "AML.T0024.001 Invert AI Model reconstructs training data from inference-API confidence scores. It does not cover inverting stored vectors, so the mapping is by analogy."
      },
      "added_in": "0.1.0",
      "last_changed_in": "0.1.0"
    },
    {
      "id": "atk-token-length-side-channel",
      "name": "Token-length side channel on streamed responses",
      "aliases": [],
      "family": "side channel",
      "scope": "ai",
      "topics": [],
      "failure_mode": "Packet sizes in an encrypted response stream reveal content to a network observer.",
      "taxonomy_refs": [],
      "paper_refs": [
        {
          "type": "arxiv",
          "id": "2403.09751",
          "title": "What Was Your Prompt? A Remote Keylogging Attack on AI Assistants",
          "first_author": "Weiss",
          "year": 2024,
          "venue": "USENIX Security 2024",
          "verified": true
        }
      ],
      "incident_refs": [],
      "srf_crosswalk": [],
      "related": [],
      "origin": "seed",
      "status": "active",
      "merged_into": null,
      "verification": {
        "checked_on": "2026-10-01",
        "checked_by": "AI agent in Cursor, session of 2026-10-01",
        "reviewed_by": null,
        "methods": [
          "arxiv-api",
          "venue-page"
        ],
        "notes": "No ATLAS v2026.08, OWASP LLM 2025, or OWASP Agentic v1.1 entry covers network side channels on response streams."
      },
      "added_in": "0.1.0",
      "last_changed_in": "0.1.0"
    },
    {
      "id": "atk-cross-tenant-leakage",
      "name": "Cross-tenant leakage in shared services",
      "aliases": [],
      "family": "multi-tenant",
      "scope": "ai",
      "topics": [
        "shared-responsibility",
        "MCP"
      ],
      "failure_mode": "One tenant's data reaches another through a shared index, cache, or service.",
      "taxonomy_refs": [
        {
          "catalog": "owasp-dsgai",
          "catalog_version": "1.0",
          "id": "DSGAI11",
          "title_in_catalog": "Cross-Context & Multi-User Conversation Bleed",
          "mapping_quality": "exact",
          "verified": true
        },
        {
          "catalog": "owasp-llm-top10",
          "catalog_version": "2025",
          "id": "LLM08:2025",
          "title_in_catalog": "Vector and Embedding Weaknesses",
          "mapping_quality": "closest",
          "verified": true
        },
        {
          "catalog": "mitre-atlas",
          "catalog_version": "v2026.08",
          "id": "AML.T0057",
          "title_in_catalog": "LLM Data Leakage",
          "mapping_quality": "closest",
          "verified": true
        }
      ],
      "paper_refs": [],
      "incident_refs": [
        {
          "type": "url",
          "id": "https://www.theregister.com/2025/06/18/asana_mcp_server_bug/",
          "label": "Asana MCP server cross-tenant data exposure, June 2025 (The Register)",
          "url": "https://www.theregister.com/2025/06/18/asana_mcp_server_bug/",
          "accessed": "2026-10-01",
          "verified": true
        },
        {
          "type": "cve",
          "id": "CVE-2026-41947",
          "label": "Dify < 1.14.2 Authorization Bypass via Trace Configuration Endpoints",
          "verified": true
        }
      ],
      "srf_crosswalk": [
        "dsgai11"
      ],
      "related": [
        "atk-embedding-inversion",
        "atk-telemetry-store-disclosure"
      ],
      "origin": "seed",
      "status": "active",
      "merged_into": null,
      "verification": {
        "checked_on": "2026-10-01",
        "checked_by": "AI agent in Cursor, session of 2026-10-01",
        "reviewed_by": null,
        "methods": [
          "atlas-release-yaml",
          "atlas-next-release-diff",
          "owasp-llm-pages",
          "dsgai-taxonomy-json",
          "cve-services-api",
          "url-fetch",
          "crosswalk-lookup"
        ],
        "notes": "LLM08:2025 covers multi-tenant leakage in a shared vector store only, so it is the closest OWASP LLM match. The RFC appendix A.5 notes that no adversary technique applies to the Asana case."
      },
      "added_in": "0.1.0",
      "last_changed_in": "0.1.0"
    },
    {
      "id": "atk-llm-output-os-command-injection",
      "name": "OS command injection through model output",
      "aliases": [],
      "family": "injection",
      "scope": "classical-reopened",
      "topics": [
        "tool-calling"
      ],
      "failure_mode": "Model output or tool arguments reach a shell, exec, or eval call, and the host runs commands neither the user nor the deployer chose.",
      "taxonomy_refs": [
        {
          "catalog": "cwe",
          "catalog_version": "4.20",
          "id": "CWE-78",
          "title_in_catalog": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "mapping_quality": "exact",
          "verified": true
        },
        {
          "catalog": "owasp-llm-top10",
          "catalog_version": "2025",
          "id": "LLM05:2025",
          "title_in_catalog": "Improper Output Handling",
          "mapping_quality": "exact",
          "verified": true
        },
        {
          "catalog": "owasp-agentic-threats",
          "catalog_version": "1.1",
          "id": "T11",
          "title_in_catalog": "Unexpected RCE and Code Attacks",
          "mapping_quality": "exact",
          "verified": true
        },
        {
          "catalog": "mitre-atlas",
          "catalog_version": "v2026.08",
          "id": "AML.T0050",
          "title_in_catalog": "Command and Scripting Interpreter",
          "mapping_quality": "closest",
          "verified": true
        }
      ],
      "paper_refs": [
        {
          "type": "arxiv",
          "id": "2309.02926",
          "title": "Demystifying RCE Vulnerabilities in LLM-Integrated Apps",
          "first_author": "Liu",
          "year": 2023,
          "venue": null,
          "verified": true
        }
      ],
      "incident_refs": [
        {
          "type": "cve",
          "id": "CVE-2023-29374",
          "label": "In LangChain through 0.0.131, the LLMMathChain chain allows prompt injection attacks that can execute arbitrary code via",
          "verified": true
        }
      ],
      "srf_crosswalk": [
        "outputcontainsconventionalinjection"
      ],
      "related": [
        "atk-sandbox-escape"
      ],
      "origin": "added",
      "status": "active",
      "merged_into": null,
      "verification": {
        "checked_on": "2026-10-01",
        "checked_by": "AI agent in Cursor, session of 2026-10-01",
        "reviewed_by": null,
        "methods": [
          "atlas-release-yaml",
          "atlas-next-release-diff",
          "owasp-llm-pages",
          "owasp-agentic-pdf",
          "cwe-api",
          "arxiv-api",
          "cve-services-api",
          "crosswalk-lookup"
        ],
        "notes": ""
      },
      "added_in": "0.1.0",
      "last_changed_in": "0.1.0"
    },
    {
      "id": "atk-llm-output-cross-site-scripting",
      "name": "Cross-site scripting through model output",
      "aliases": [],
      "family": "injection",
      "scope": "classical-reopened",
      "topics": [],
      "failure_mode": "Script or markup in model output runs in the user's browser with the application's privileges.",
      "taxonomy_refs": [
        {
          "catalog": "cwe",
          "catalog_version": "4.20",
          "id": "CWE-79",
          "title_in_catalog": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "mapping_quality": "exact",
          "verified": true
        },
        {
          "catalog": "owasp-llm-top10",
          "catalog_version": "2025",
          "id": "LLM05:2025",
          "title_in_catalog": "Improper Output Handling",
          "mapping_quality": "exact",
          "verified": true
        }
      ],
      "paper_refs": [],
      "incident_refs": [],
      "srf_crosswalk": [
        "outputcontainsconventionalinjection"
      ],
      "related": [
        "atk-zero-click-output-exfiltration"
      ],
      "origin": "added",
      "status": "active",
      "merged_into": null,
      "verification": {
        "checked_on": "2026-10-01",
        "checked_by": "AI agent in Cursor, session of 2026-10-01",
        "reviewed_by": null,
        "methods": [
          "owasp-llm-pages",
          "cwe-api",
          "crosswalk-lookup"
        ],
        "notes": ""
      },
      "added_in": "0.1.0",
      "last_changed_in": "0.1.0"
    },
    {
      "id": "atk-nl-to-query-sql-injection",
      "name": "SQL injection through natural-language query generation",
      "aliases": [],
      "family": "injection",
      "scope": "classical-reopened",
      "topics": [
        "tool-calling"
      ],
      "failure_mode": "A natural-language request becomes a database query that reads or changes rows outside the requesting user's scope.",
      "taxonomy_refs": [
        {
          "catalog": "cwe",
          "catalog_version": "4.20",
          "id": "CWE-89",
          "title_in_catalog": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "mapping_quality": "exact",
          "verified": true
        },
        {
          "catalog": "owasp-llm-top10",
          "catalog_version": "2025",
          "id": "LLM05:2025",
          "title_in_catalog": "Improper Output Handling",
          "mapping_quality": "exact",
          "verified": true
        },
        {
          "catalog": "owasp-dsgai",
          "catalog_version": "1.0",
          "id": "DSGAI12",
          "title_in_catalog": "Unsafe Natural-Language Data Gateways",
          "mapping_quality": "exact",
          "verified": true
        }
      ],
      "paper_refs": [],
      "incident_refs": [],
      "srf_crosswalk": [
        "dsgai12",
        "outputcontainsconventionalinjection"
      ],
      "related": [
        "atk-excessive-agency"
      ],
      "origin": "added",
      "status": "active",
      "merged_into": null,
      "verification": {
        "checked_on": "2026-10-01",
        "checked_by": "AI agent in Cursor, session of 2026-10-01",
        "reviewed_by": null,
        "methods": [
          "owasp-llm-pages",
          "dsgai-taxonomy-json",
          "cwe-api",
          "crosswalk-lookup"
        ],
        "notes": ""
      },
      "added_in": "0.1.0",
      "last_changed_in": "0.1.0"
    },
    {
      "id": "atk-llm-output-path-traversal",
      "name": "Path traversal through model-built file paths",
      "aliases": [],
      "family": "injection",
      "scope": "classical-reopened",
      "topics": [
        "tool-calling"
      ],
      "failure_mode": "A file path built from model output resolves outside the directory the tool was meant to touch.",
      "taxonomy_refs": [
        {
          "catalog": "cwe",
          "catalog_version": "4.20",
          "id": "CWE-22",
          "title_in_catalog": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "mapping_quality": "exact",
          "verified": true
        },
        {
          "catalog": "owasp-llm-top10",
          "catalog_version": "2025",
          "id": "LLM05:2025",
          "title_in_catalog": "Improper Output Handling",
          "mapping_quality": "exact",
          "verified": true
        }
      ],
      "paper_refs": [],
      "incident_refs": [],
      "srf_crosswalk": [
        "outputcontainsconventionalinjection"
      ],
      "related": [
        "atk-sandbox-escape"
      ],
      "origin": "added",
      "status": "active",
      "merged_into": null,
      "verification": {
        "checked_on": "2026-10-01",
        "checked_by": "AI agent in Cursor, session of 2026-10-01",
        "reviewed_by": null,
        "methods": [
          "owasp-llm-pages",
          "cwe-api",
          "crosswalk-lookup"
        ],
        "notes": ""
      },
      "added_in": "0.1.0",
      "last_changed_in": "0.1.0"
    },
    {
      "id": "atk-agent-tool-ssrf",
      "name": "Server-side request forgery through agent fetch tools",
      "aliases": [],
      "family": "injection",
      "scope": "classical-reopened",
      "topics": [
        "tool-calling",
        "MCP"
      ],
      "failure_mode": "An agent's fetch or browse tool requests an internal address for an attacker, so data behind the network boundary reaches the attacker.",
      "taxonomy_refs": [
        {
          "catalog": "cwe",
          "catalog_version": "4.20",
          "id": "CWE-918",
          "title_in_catalog": "Server-Side Request Forgery (SSRF)",
          "mapping_quality": "exact",
          "verified": true
        },
        {
          "catalog": "owasp-llm-top10",
          "catalog_version": "2025",
          "id": "LLM05:2025",
          "title_in_catalog": "Improper Output Handling",
          "mapping_quality": "closest",
          "verified": true
        },
        {
          "catalog": "mitre-atlas",
          "catalog_version": "v2026.08",
          "id": "AML.T0122",
          "title_in_catalog": "Exploitation of Remote Services",
          "mapping_quality": "closest",
          "verified": true
        }
      ],
      "paper_refs": [],
      "incident_refs": [],
      "srf_crosswalk": [
        "outputcontainsconventionalinjection"
      ],
      "related": [
        "atk-indirect-prompt-injection",
        "atk-excessive-agency"
      ],
      "origin": "added",
      "status": "active",
      "merged_into": null,
      "verification": {
        "checked_on": "2026-10-01",
        "checked_by": "AI agent in Cursor, session of 2026-10-01",
        "reviewed_by": null,
        "methods": [
          "atlas-release-yaml",
          "atlas-next-release-diff",
          "owasp-llm-pages",
          "cwe-api",
          "crosswalk-lookup"
        ],
        "notes": "LLM05:2025 names SSRF as an outcome of improper output handling but gives no scenario. AML.T0122 mentions server-side request flaws in shared services."
      },
      "added_in": "0.1.0",
      "last_changed_in": "0.1.0"
    },
    {
      "id": "atk-agent-config-credential-exposure",
      "name": "Credential exposure in agent configuration",
      "aliases": [],
      "family": "identity",
      "scope": "classical-reopened",
      "topics": [
        "agent-identity",
        "MCP"
      ],
      "failure_mode": "Keys and tokens an agent needs for its tools sit in readable configuration, so whoever can read the configuration or steer the agent gains the agent's access.",
      "taxonomy_refs": [
        {
          "catalog": "mitre-atlas",
          "catalog_version": "v2026.08",
          "id": "AML.T0083",
          "title_in_catalog": "Credentials from AI Agent Configuration",
          "mapping_quality": "exact",
          "verified": true
        },
        {
          "catalog": "mitre-atlas",
          "catalog_version": "v2026.08",
          "id": "AML.T0098",
          "title_in_catalog": "AI Agent Tool Credential Harvesting",
          "mapping_quality": "closest",
          "verified": true
        },
        {
          "catalog": "cwe",
          "catalog_version": "4.20",
          "id": "CWE-522",
          "title_in_catalog": "Insufficiently Protected Credentials",
          "mapping_quality": "exact",
          "verified": true
        },
        {
          "catalog": "cwe",
          "catalog_version": "4.20",
          "id": "CWE-312",
          "title_in_catalog": "Cleartext Storage of Sensitive Information",
          "mapping_quality": "closest",
          "verified": true
        },
        {
          "catalog": "owasp-dsgai",
          "catalog_version": "1.0",
          "id": "DSGAI02",
          "title_in_catalog": "Agent Identity & Credential Exposure",
          "mapping_quality": "exact",
          "verified": true
        }
      ],
      "paper_refs": [],
      "incident_refs": [
        {
          "type": "cve",
          "id": "CVE-2025-11749",
          "label": "AI Engine <= 3.1.3 - Unauthenticated Sensitive Information Exposure to Privilege Escalation",
          "verified": true
        }
      ],
      "srf_crosswalk": [
        "dsgai02"
      ],
      "related": [
        "atk-confused-deputy-delegation",
        "atk-system-prompt-extraction"
      ],
      "origin": "added",
      "status": "active",
      "merged_into": null,
      "verification": {
        "checked_on": "2026-10-01",
        "checked_by": "AI agent in Cursor, session of 2026-10-01",
        "reviewed_by": null,
        "methods": [
          "atlas-release-yaml",
          "atlas-next-release-diff",
          "dsgai-taxonomy-json",
          "cwe-api",
          "cve-services-api",
          "crosswalk-lookup"
        ],
        "notes": "CVE-2025-11749 exposes a bearer token through an MCP endpoint when a no-auth URL is enabled."
      },
      "added_in": "0.1.0",
      "last_changed_in": "0.1.0"
    }
  ]
}
