| API Abuse | api-abuse | tool-use | high | Exploits AI-connected APIs to trigger unintended actions beyond intended scope |
| Browser Exploitation | browser-exploitation | tool-use | high | Exploits AI browser or web automation tools to steal cookies, execute XSS, or perform unauthorized web actions |
| Calendar Manipulation | calendar-manipulation | tool-use | medium | Manipulates calendar events via AI assistant to disrupt schedules or exfiltrate meeting data |
| CI/CD Injection | ci-cd-injection | single-turn | critical | Injects malicious steps into CI/CD pipelines via AI code review or automated PR assistance |
| Cloud Resource Abuse | cloud-resource-abuse | tool-use | critical | Abuses cloud APIs through AI to provision unauthorized resources, exfiltrate data, or escalate IAM privileges |
| Container Escape | container-escape | tool-use | critical | Attempts container escape through AI tools by exploiting privileged mounts or kernel interfaces |
| Database Manipulation | database-manipulation | tool-use | critical | SQL manipulation through AI database access tools to read, modify, or destroy data |
| DNS Manipulation | dns-manipulation | single-turn | high | DNS rebinding or manipulation via AI tools to bypass network controls or exfiltrate data |
| Email Injection | email-injection | single-turn | high | Exploits email-connected AI assistants to exfiltrate data or send unauthorized emails |
| File System Traversal | file-system-traversal | tool-use | critical | Path traversal through AI file access tools to read or write files outside the intended directory |
| Notification Spam | notification-spam | tool-use | medium | Abuses notification systems through AI to flood users, harvest responses, or send phishing content |
| OAuth Manipulation | oauth-manipulation | tool-use | critical | Exploits OAuth flows in AI integrations to gain unauthorized access or escalate privileges |
| Payment Manipulation | payment-manipulation | tool-use | critical | Manipulates payment APIs via AI to issue fraudulent refunds, transfer funds, or modify pricing |
| Slack Injection | slack-injection | single-turn | high | Injects malicious instructions via Slack or Teams messages to hijack AI assistant actions |
| Webhook Exploitation | webhook-exploitation | tool-use | high | Abuses webhook integrations to exfiltrate data or trigger unauthorized actions |