| Agent Command Injection | agent-command-injection | tool-use | critical | Sandbox escape via path traversal and command chaining |
| Agent Config Discovery | agent-config-discovery | tool-use | high | Probe model to reveal tool definitions, system prompt, and agent config files |
| Agent Config Manipulation | agent-config-manipulation | tool-use | critical | Production hotfix pretext to write security-disabling configuration |
| Agent Credential Theft | agent-credential-theft | tool-use | critical | Security audit pretext to read credentials then exfiltrate via email |
| Agent Data Destruction | agent-data-destruction | tool-use | critical | Migration cleanup pretext to delete files and drop database tables |
| Agent Data Exfiltration | agent-data-exfiltration | tool-use | critical | DevOps monitoring pretext to read system data then POST to external endpoint |
| Agent Plugin Hijack | agent-plugin-hijack | tool-use | high | Indirect prompt injection via fetched content to trigger unauthorized tool calls |
| Agent Tool Credential Harvest | agent-tool-credential-harvest | tool-use | critical | Systematic credential probing across filesystem, environment, database, and cloud configs |
| XPIA Document Injection | xpia-document | tool-use | critical | Indirect prompt injection via fetched document containing hidden instructions |
| XPIA Email Injection | xpia-email | tool-use | critical | Indirect prompt injection via email content containing hidden forwarding instructions |
| XPIA RAG Poisoning | xpia-rag | tool-use | critical | Indirect prompt injection via poisoned RAG knowledge base search result |