Cite checked ids instead of recalled ones
The claims test builds a table of
published attack classes in its C-attacks step. Pack 1.0.8 reads
this inventory by default and builds rows from it first, so those
rows carry ids resolved against ATLAS v2026.08, OWASP LLM Top 10
2025, OWASP Agentic AI Threats and Mitigations v1.1, OWASP GenAI
Data Security 1.0, or CWE 4.20. Classes the inventory lacks still
get ids from model memory, marked unresolved_unpinned.
A threat model or red-team scope can start from the same list, then
follow a class's srf_crosswalk ids, where present, into
/data/threats.json for the SRF layer
and the accountable persona per operating model. The inventory sets
no severity and holds no procedures: each entry says who loses what,
under what condition.
What checking the seed table changed
31 entries came from the attack table of a claims-test run against the CoSAI AI Telemetry RFC v0.6, where every catalog and paper id had been filled from memory. Checking them against their sources changed refs on 11 entries.
- All 14 arXiv ids in the seed table resolve, and each first author matches the table.
- All 13 ATLAS ids in the seed table exist at v2026.08 and keep their names in v2026.09. Six seed rows cited a parent technique or a looser fit where ATLAS has a narrower one; zero-click exfiltration, for example, now maps to
AML.T0077LLM Response Rendering. Sandbox escape had no ATLAS id and now maps toAML.T0105Escape to Host. - ATLAS case study
AML.CS0059tags the EchoLeak injection step asAML.T0051.002Triggered. The RFC's attack appendix tags it.001Indirect. EchoLeak now sits under zero-click exfiltration. - MCP tool poisoning had only a blog post. ATLAS case study
AML.CS0054cites that post and gives it a stable id;AML.T0109and CVE-2025-54136 cover tool definitions that change after approval. - Injection carried by telemetry into LLM-assisted triage was mapped by analogy, with no paper. Three 2026 arXiv papers show log fields acting as attacker-controlled content that an LLM triage tool reads. That is the data-channel case
AML.T0051.001Indirect covers, so the ref is now graded exact. - The OWASP Agentic AI Threats PDF now served is v1.1 (December 2025). It adds T16 and T17; the seed's T1, T3, T7, T8, T9, T10, and T11 keep their titles.
Inventory
Grades: exact the catalog text covers the class without stretching; closest it covers part of the class or a neighbor and is the best entry available; analogy it describes a different mechanism with a similar effect. The source file is /data/attack-inventory.json, with its schema at /data/attack-inventory.schema.json.
| Class | Failure mode | Catalog refs | Papers and incidents | SRF crosswalk |
|---|---|---|---|---|
| The inventory loads from /data/attack-inventory.json. | ||||
Catalog versions
Each catalog ref records the version below. Where a file was downloaded, the SHA-256 or commit lets a reviewer confirm the same bytes were read.
| Catalog | Version | Released | Pin |
|---|---|---|---|
| Catalog pins load from the same file. | |||
What this version cannot answer
- An AI agent ran every check in this version.
reviewed_byis null on all 37 entries until a person confirms them. - A verified paper ref means the arXiv id resolves and the title and first author match. Only the three telemetry-triage papers had their abstracts read. The Agents of Chaos cases cited for display-name spoofing and false self-reports were not reread.
- Three classes have no exact catalog entry: deceptive agent self-report (OWASP Agentic T7 is the closest), observability-plane evasion (
AML.T0081covers a disabled setting, not a starved guardrail), and the token-length side channel (no ATLAS, OWASP LLM, or OWASP Agentic entry). - Eight classes have no row in /data/threats.json, so the inventory cannot name an SRF layer or accountable persona for them: agent memory poisoning, hallucinated package squatting, sandbox escape, deceptive agent self-report, repudiation by log tampering, observability-plane evasion, approval fatigue, and the token-length side channel.
- BIML LLM24 ids are not mapped. They name risk areas broader than these classes, and choosing between them needs a reviewer.
- ATLAS v2026.09 is out and adds
AML.T0129Triggers in Multimodal Inputs, which may fit multimodal instruction injection more narrowly. The pin stays at v2026.08 because the RFC cites that release. - The list started from one telemetry RFC's attack table plus six classical weaknesses. ATLAS techniques outside that topic, such as
AML.T0015model evasion against classic ML classifiers,AML.T0041physical-environment attacks, andAML.T0052.001deepfake-assisted phishing, have no entry of their own.
Change, verify, export
Edit the JSON, bump inventory_version (patch for a ref
fix, minor for a new entry, major for a removed field or changed id),
and add one changelog line naming the id and the reason. Then run the
verifier. It fails on a dangling id, a ref whose catalog version
differs from the pin, a verified ref with no check date or method,
or an em dash in any text field. It warns when a newer catalog
release has been seen or a URL ref is more than 180 days old.
python3 build/verify_attack_inventory.py
A claims-test run reads the whole file unless it is given an export. To limit a run to the draft's topics, export them and attach the result. Rows are numbered ATT-01 upward after the filter; draft overlap stays null for the run to judge.
python3 build/export_attack_inventory.py --topics telemetry,MCP --format md
python3 build/export_attack_inventory.py --scope agentic --out attacks.json
Recheck the inventory when ATLAS publishes a release, when OWASP revises the LLM Top 10 or the Agentic AI Threats document, when a CoSAI WS2 draft cites a new incident, or when a claims-test run finds a class missing here.