critical
ci-cd-injection · single-turn · OWASP: LLM03 · MITRE: AML.T0054, AML.T0068Injects malicious steps into CI/CD pipelines via AI code review or automated PR assistanceRun it:critical
cloud-resource-abuse · tool-use · OWASP: LLM03 · MITRE: AML.T0054, AML.T0068Abuses cloud APIs through AI to provision unauthorized resources, exfiltrate data, or escalate IAM privilegesRun it:critical
container-escape · tool-use · OWASP: LLM03 · MITRE: AML.T0054, AML.T0068Attempts container escape through AI tools by exploiting privileged mounts or kernel interfacesRun it:critical
database-manipulation · tool-use · OWASP: LLM03 · MITRE: AML.T0054, AML.T0068SQL manipulation through AI database access tools to read, modify, or destroy dataRun it:critical
file-system-traversal · tool-use · OWASP: LLM03 · MITRE: AML.T0054, AML.T0068Path traversal through AI file access tools to read or write files outside the intended directoryRun it:critical
oauth-manipulation · tool-use · OWASP: LLM03 · MITRE: AML.T0054, AML.T0068Exploits OAuth flows in AI integrations to gain unauthorized access or escalate privilegesRun it:critical
payment-manipulation · tool-use · OWASP: LLM03 · MITRE: AML.T0054, AML.T0068Manipulates payment APIs via AI to issue fraudulent refunds, transfer funds, or modify pricingRun it:high
api-abuse · tool-use · OWASP: LLM03 · MITRE: AML.T0054, AML.T0068Exploits AI-connected APIs to trigger unintended actions beyond intended scopeRun it:high
browser-exploitation · tool-use · OWASP: LLM03 · MITRE: AML.T0054, AML.T0068Exploits AI browser or web automation tools to steal cookies, execute XSS, or perform unauthorized web actionsRun it:high
dns-manipulation · single-turn · OWASP: LLM03 · MITRE: AML.T0054, AML.T0068DNS rebinding or manipulation via AI tools to bypass network controls or exfiltrate dataRun it:high
email-injection · single-turn · OWASP: LLM03 · MITRE: AML.T0054, AML.T0068Exploits email-connected AI assistants to exfiltrate data or send unauthorized emailsRun it:high
slack-injection · single-turn · OWASP: LLM03 · MITRE: AML.T0054, AML.T0068Injects malicious instructions via Slack or Teams messages to hijack AI assistant actionsRun it:high
webhook-exploitation · tool-use · OWASP: LLM03 · MITRE: AML.T0054, AML.T0068Abuses webhook integrations to exfiltrate data or trigger unauthorized actionsRun it:medium
calendar-manipulation · tool-use · OWASP: LLM03 · MITRE: AML.T0054, AML.T0068Manipulates calendar events via AI assistant to disrupt schedules or exfiltrate meeting dataRun it:medium
notification-spam · tool-use · OWASP: LLM03 · MITRE: AML.T0054, AML.T0068Abuses notification systems through AI to flood users, harvest responses, or send phishing contentRun it: