Framework in practice

Attack inventory

37 published attack classes against AI models, LLM applications, and agents. Each class states a failure mode and lists MITRE ATLAS, OWASP, CWE, arXiv, and CVE ids. Every id was checked against a pinned catalog version or its source record on 1 October 2026. The file assigns no owners: 29 classes link to the SRF threat crosswalk, which names the accountable persona, and 8 have no crosswalk row yet.

Cite checked ids instead of recalled ones

The claims test builds a table of published attack classes in its C-attacks step. Pack 1.0.8 reads this inventory by default and builds rows from it first, so those rows carry ids resolved against ATLAS v2026.08, OWASP LLM Top 10 2025, OWASP Agentic AI Threats and Mitigations v1.1, OWASP GenAI Data Security 1.0, or CWE 4.20. Classes the inventory lacks still get ids from model memory, marked unresolved_unpinned.

A threat model or red-team scope can start from the same list, then follow a class's srf_crosswalk ids, where present, into /data/threats.json for the SRF layer and the accountable persona per operating model. The inventory sets no severity and holds no procedures: each entry says who loses what, under what condition.

37
classes: 19 AI, 12 agentic, 6 classical weaknesses that agents reopen
142
refs: 102 catalog, 23 paper, 17 incident, all checked
63 / 38 / 1
catalog refs graded exact, closest, and analogy
3
classes with no exact catalog entry

What checking the seed table changed

31 entries came from the attack table of a claims-test run against the CoSAI AI Telemetry RFC v0.6, where every catalog and paper id had been filled from memory. Checking them against their sources changed refs on 11 entries.

  • All 14 arXiv ids in the seed table resolve, and each first author matches the table.
  • All 13 ATLAS ids in the seed table exist at v2026.08 and keep their names in v2026.09. Six seed rows cited a parent technique or a looser fit where ATLAS has a narrower one; zero-click exfiltration, for example, now maps to AML.T0077 LLM Response Rendering. Sandbox escape had no ATLAS id and now maps to AML.T0105 Escape to Host.
  • ATLAS case study AML.CS0059 tags the EchoLeak injection step as AML.T0051.002 Triggered. The RFC's attack appendix tags it .001 Indirect. EchoLeak now sits under zero-click exfiltration.
  • MCP tool poisoning had only a blog post. ATLAS case study AML.CS0054 cites that post and gives it a stable id; AML.T0109 and CVE-2025-54136 cover tool definitions that change after approval.
  • Injection carried by telemetry into LLM-assisted triage was mapped by analogy, with no paper. Three 2026 arXiv papers show log fields acting as attacker-controlled content that an LLM triage tool reads. That is the data-channel case AML.T0051.001 Indirect covers, so the ref is now graded exact.
  • The OWASP Agentic AI Threats PDF now served is v1.1 (December 2025). It adds T16 and T17; the seed's T1, T3, T7, T8, T9, T10, and T11 keep their titles.

Inventory

Grades: exact the catalog text covers the class without stretching; closest it covers part of the class or a neighbor and is the best entry available; analogy it describes a different mechanism with a similar effect. The source file is /data/attack-inventory.json, with its schema at /data/attack-inventory.schema.json.

Class Failure mode Catalog refs Papers and incidents SRF crosswalk
The inventory loads from /data/attack-inventory.json.

Catalog versions

Each catalog ref records the version below. Where a file was downloaded, the SHA-256 or commit lets a reviewer confirm the same bytes were read.

Catalog Version Released Pin
Catalog pins load from the same file.

What this version cannot answer

  • An AI agent ran every check in this version. reviewed_by is null on all 37 entries until a person confirms them.
  • A verified paper ref means the arXiv id resolves and the title and first author match. Only the three telemetry-triage papers had their abstracts read. The Agents of Chaos cases cited for display-name spoofing and false self-reports were not reread.
  • Three classes have no exact catalog entry: deceptive agent self-report (OWASP Agentic T7 is the closest), observability-plane evasion (AML.T0081 covers a disabled setting, not a starved guardrail), and the token-length side channel (no ATLAS, OWASP LLM, or OWASP Agentic entry).
  • Eight classes have no row in /data/threats.json, so the inventory cannot name an SRF layer or accountable persona for them: agent memory poisoning, hallucinated package squatting, sandbox escape, deceptive agent self-report, repudiation by log tampering, observability-plane evasion, approval fatigue, and the token-length side channel.
  • BIML LLM24 ids are not mapped. They name risk areas broader than these classes, and choosing between them needs a reviewer.
  • ATLAS v2026.09 is out and adds AML.T0129 Triggers in Multimodal Inputs, which may fit multimodal instruction injection more narrowly. The pin stays at v2026.08 because the RFC cites that release.
  • The list started from one telemetry RFC's attack table plus six classical weaknesses. ATLAS techniques outside that topic, such as AML.T0015 model evasion against classic ML classifiers, AML.T0041 physical-environment attacks, and AML.T0052.001 deepfake-assisted phishing, have no entry of their own.

Change, verify, export

Edit the JSON, bump inventory_version (patch for a ref fix, minor for a new entry, major for a removed field or changed id), and add one changelog line naming the id and the reason. Then run the verifier. It fails on a dangling id, a ref whose catalog version differs from the pin, a verified ref with no check date or method, or an em dash in any text field. It warns when a newer catalog release has been seen or a URL ref is more than 180 days old.

python3 build/verify_attack_inventory.py

A claims-test run reads the whole file unless it is given an export. To limit a run to the draft's topics, export them and attach the result. Rows are numbered ATT-01 upward after the filter; draft overlap stays null for the run to judge.

python3 build/export_attack_inventory.py --topics telemetry,MCP --format md
python3 build/export_attack_inventory.py --scope agentic --out attacks.json

Recheck the inventory when ATLAS publishes a release, when OWASP revises the LLM Top 10 or the Agentic AI Threats document, when a CoSAI WS2 draft cites a new incident, or when a claims-test run finds a class missing here.