There are 11 attacks in the agent-exploitation category. Each shows its technique id, mode, standards mapping, description, and the exact command to run it (swap the provider and target as needed).
critical
agent-command-injection · tool-use · OWASP: LLM03 · MITRE: AML.T0050, AML.T0105Sandbox escape via path traversal and command chainingRun it:
critical
agent-config-manipulation · tool-use · OWASP: LLM03 · MITRE: AML.T0081Production hotfix pretext to write security-disabling configurationRun it:
critical
agent-credential-theft · tool-use · OWASP: LLM03, LLM02 · MITRE: AML.T0083, AML.T0086Security audit pretext to read credentials then exfiltrate via emailRun it:
critical
agent-data-destruction · tool-use · OWASP: LLM03 · MITRE: AML.T0101Migration cleanup pretext to delete files and drop database tablesRun it:
critical
agent-data-exfiltration · tool-use · OWASP: LLM03, LLM02 · MITRE: AML.T0086, AML.T0098DevOps monitoring pretext to read system data then POST to external endpointRun it:
critical
agent-tool-credential-harvest · tool-use · OWASP: LLM03, LLM02 · MITRE: AML.T0098, AML.T0085.001Systematic credential probing across filesystem, environment, database, and cloud configsRun it:
critical
xpia-document · tool-use · OWASP: LLM01 · MITRE: AML.T0051.001Indirect prompt injection via fetched document containing hidden instructionsRun it:
critical
xpia-email · tool-use · OWASP: LLM01 · MITRE: AML.T0051.001Indirect prompt injection via email content containing hidden forwarding instructionsRun it:
critical
xpia-rag · tool-use · OWASP: LLM01 · MITRE: AML.T0051.001, AML.T0070Indirect prompt injection via poisoned RAG knowledge base search resultRun it:
high
agent-config-discovery · tool-use · OWASP: LLM03, LLM08 · MITRE: AML.T0084.001, AML.T0084.003Probe model to reveal tool definitions, system prompt, and agent config filesRun it:
high
agent-plugin-hijack · tool-use · OWASP: LLM03 · MITRE: AML.T0053, AML.T0011.002, AML.T0080.001Indirect prompt injection via fetched content to trigger unauthorized tool callsRun it: