{
  "standard": "ATD — Agentic Threat Detection",
  "status": "Editor's Draft",
  "version": "0.1.0",
  "generated": "2026-06-14",
  "license": "MIT",
  "stats": {
    "techniques": 81,
    "withLiveRule": 47,
    "withCve": 30,
    "tactics": 9
  },
  "tactics": [
    {
      "id": "ATD-TA1",
      "name": "Protocol & Interconnect"
    },
    {
      "id": "ATD-TA2",
      "name": "Memory & Context Integrity"
    },
    {
      "id": "ATD-TA3",
      "name": "Goal, Planning & Reasoning"
    },
    {
      "id": "ATD-TA4",
      "name": "Identity, Authz & Delegation"
    },
    {
      "id": "ATD-TA5",
      "name": "Tool & Supply Chain"
    },
    {
      "id": "ATD-TA6",
      "name": "Execution & Autonomy"
    },
    {
      "id": "ATD-TA7",
      "name": "Multi-Agent Dynamics"
    },
    {
      "id": "ATD-TA8",
      "name": "Model-Intrinsic & Governance"
    },
    {
      "id": "ATD-TA9",
      "name": "Agentic Commerce (forward)"
    }
  ],
  "techniques": [
    {
      "atd_id": "ATD-T0001",
      "schema_version": "0.1.0",
      "title": "Shell metacharacter injection through MCP tool parameters",
      "tactic": "ATD-TA1",
      "abstraction": "base",
      "status": "experimental",
      "severity": "high",
      "description": "Unsanitized MCP tool input reaches execSync/exec, yielding RCE on the server host.",
      "detection_surface": [
        "tool_input",
        "tool_response"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI05",
          "ASI02"
        ],
        "mitre_atlas": [
          "AML.T0053"
        ],
        "cwe": [
          "CWE-77"
        ]
      },
      "references": [
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-53355"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27001"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-21668"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5831"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47708"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6825"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3271"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42271"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5602"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5603"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-13545"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15035"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42850"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-30310"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-30616"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-30617"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32622"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41265"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41497"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4198"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4399"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48116"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5007"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5619"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5802"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5833"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6108"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6118"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6130"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7061"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7211"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7215"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7416"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7443"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7446"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7593"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7600"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7628"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7642"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7653"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7730"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7812"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33246"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33249"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-55319"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-26133"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54449"
        }
      ],
      "atr_rule": "ATR-2026-01927"
    },
    {
      "atd_id": "ATD-T0002",
      "schema_version": "0.1.0",
      "title": "curl-fallback command injection in an MCP server",
      "tactic": "ATD-TA1",
      "abstraction": "base",
      "status": "experimental",
      "severity": "high",
      "description": "A failed fetch falls back to exec'ing curl with an unsanitized URL, enabling RCE.",
      "detection_surface": [
        "tool_input",
        "tool_response"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI05",
          "ASI02"
        ],
        "mitre_atlas": [
          "AML.T0053"
        ],
        "cwe": [
          "CWE-420"
        ]
      },
      "references": [
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-53967"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40217"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-15061"
        }
      ],
      "atr_rule": "ATR-2026-01928"
    },
    {
      "atd_id": "ATD-T0003",
      "schema_version": "0.1.0",
      "title": "Command injection in a scaffolded MCP stdio server",
      "tactic": "ATD-TA1",
      "abstraction": "base",
      "status": "experimental",
      "severity": "critical",
      "description": "Generated server concatenates tool input into exec(), giving RCE to anything built from it.",
      "detection_surface": [
        "tool_input",
        "tool_response"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI04",
          "ASI05"
        ],
        "mitre_atlas": [
          "AML.T0010.005"
        ],
        "cwe": [
          "CWE-78"
        ]
      },
      "references": [
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-54994"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24763"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25157"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25593"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-26323"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27487"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-41228"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-35216"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46339"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55786"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34955"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34937"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34540"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6019"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24698"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44170"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44454"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55427"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55798"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-23653"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-26129"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-26164"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33111"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41090"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42824"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42827"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42895"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45497"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-64340"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-71336"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-23882"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-29783"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-30635"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-30861"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-31246"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39417"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40088"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40111"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48719"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5058"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5059"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54149"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55249"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56274"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59726"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23316"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24252"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-55284"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61591"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0286"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41857"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58459"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58479"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-62392"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48561"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55145"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47751"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-62312"
        }
      ],
      "atr_rule": "ATR-2026-00577"
    },
    {
      "atd_id": "ATD-T0004",
      "schema_version": "0.1.0",
      "title": "Line-jumping — tool-description injection at listing time",
      "tactic": "ATD-TA1",
      "abstraction": "base",
      "status": "experimental",
      "severity": "high",
      "description": "Hidden instructions in a tool description enter the model context at tools/list, before any call.",
      "detection_surface": [
        "tool_input",
        "tool_response"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI04",
          "ASI01"
        ],
        "mitre_atlas": [
          "AML.T0110",
          "AML.T0104"
        ],
        "cwe": [
          "CWE-1427"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://blog.trailofbits.com/2025/04/21/jumping-the-line-how-mcp-servers-can-attack-you-before-you-ever-use-them/"
        }
      ],
      "atr_rule": "ATR-2026-00579"
    },
    {
      "atd_id": "ATD-T0005",
      "schema_version": "0.1.0",
      "title": "Rug pull — silent mutation of an approved tool",
      "tactic": "ATD-TA1",
      "abstraction": "base",
      "status": "experimental",
      "severity": "high",
      "description": "A server approved once later changes a tool's definition with no integrity re-check.",
      "detection_surface": [
        "tool_input",
        "tool_response"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI04"
        ],
        "mitre_atlas": [
          "AML.T0109",
          "AML.T0110"
        ],
        "cwe": [
          "CWE-494"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://github.com/invariantlabs-ai/mcp-injection-experiments"
        }
      ],
      "atr_rule": "ATR-2026-00581"
    },
    {
      "atd_id": "ATD-T0006",
      "schema_version": "0.1.0",
      "title": "Missing-auth MCP proxy command execution",
      "tactic": "ATD-TA1",
      "abstraction": "base",
      "status": "experimental",
      "severity": "critical",
      "description": "No auth between client and MCP proxy lets any local/web-driven request spawn MCP processes.",
      "detection_surface": [
        "tool_input",
        "tool_response"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI03",
          "ASI05"
        ],
        "mitre_atlas": [],
        "cwe": [
          "CWE-306"
        ]
      },
      "references": [
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49596"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3248"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50027"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53512"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54309"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47391"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-31944"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34200"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42856"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44830"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44895"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-49471"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50287"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5029"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55605"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58446"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58473"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59706"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59822"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54504"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54446"
        }
      ]
    },
    {
      "atd_id": "ATD-T0007",
      "schema_version": "0.1.0",
      "title": "RCE from a malicious upstream MCP server",
      "tactic": "ATD-TA1",
      "abstraction": "base",
      "status": "experimental",
      "severity": "critical",
      "description": "A client is RCE'd via a crafted authorization_endpoint URL in an untrusted server's response.",
      "detection_surface": [
        "tool_input",
        "tool_response"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI04",
          "ASI05"
        ],
        "mitre_atlas": [
          "AML.T0010.005"
        ],
        "cwe": [
          "CWE-78"
        ]
      },
      "references": [
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-6514"
        }
      ]
    },
    {
      "atd_id": "ATD-T0008",
      "schema_version": "0.1.0",
      "title": "DNS-rebinding to a localhost MCP server",
      "tactic": "ATD-TA1",
      "abstraction": "base",
      "status": "experimental",
      "severity": "high",
      "description": "A malicious page rebinds DNS to reach an unauthenticated localhost MCP server cross-origin.",
      "detection_surface": [
        "tool_input",
        "tool_response"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI07",
          "ASI03"
        ],
        "mitre_atlas": [],
        "cwe": [
          "CWE-1188"
        ]
      },
      "references": [
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-66416"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-66414"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34742"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-61439"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48022"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24477"
        }
      ]
    },
    {
      "atd_id": "ATD-T0009",
      "schema_version": "0.1.0",
      "title": "Session ID / auth token placed in a URL query string",
      "tactic": "ATD-TA1",
      "abstraction": "base",
      "status": "experimental",
      "severity": "medium",
      "description": "A credential in the query string leaks via server logs, proxies, CDNs, history, and Referer.",
      "detection_surface": [
        "tool_input",
        "tool_response"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI03",
          "ASI07"
        ],
        "mitre_atlas": [],
        "cwe": [
          "CWE-598"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://vulnerablemcp.info/"
        }
      ],
      "atr_rule": "ATR-2026-00580"
    },
    {
      "atd_id": "ATD-T0010",
      "schema_version": "0.1.0",
      "title": "Serialized-object smuggling through an LLM response field",
      "tactic": "ATD-TA2",
      "abstraction": "base",
      "status": "experimental",
      "severity": "critical",
      "description": "Injected output carries a serialization marker; deserialization rehydrates it as trusted and exfiltrates secrets.",
      "detection_surface": [
        "memory_op"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI06",
          "ASI01"
        ],
        "mitre_atlas": [
          "AML.T0051.001"
        ],
        "cwe": [
          "CWE-502"
        ]
      },
      "references": [
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-68664"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12029"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27520"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32375"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-44228"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-0573"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45134"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5998"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28277"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44843"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-68665"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1839"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-31239"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23249"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23303"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33212"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33213"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33214"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33226"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33241"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33243"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33245"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33252"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33253"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24157"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24159"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24162"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24164"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24165"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24216"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24228"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54499"
        }
      ]
    },
    {
      "atd_id": "ATD-T0011",
      "schema_version": "0.1.0",
      "title": "Persistent memory / context-store poisoning",
      "tactic": "ATD-TA2",
      "abstraction": "base",
      "status": "experimental",
      "severity": "high",
      "description": "Attacker-controlled content is written into data the agent later reads back as trusted context.",
      "detection_surface": [
        "memory_op"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI06"
        ],
        "mitre_atlas": [
          "AML.T0080"
        ],
        "cwe": [
          "CWE-349"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://atlas.mitre.org/"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-35641"
        }
      ]
    },
    {
      "atd_id": "ATD-T0012",
      "schema_version": "0.1.0",
      "title": "Indirect prompt injection via tool / API response",
      "tactic": "ATD-TA3",
      "abstraction": "base",
      "status": "experimental",
      "severity": "high",
      "description": "Malicious text in returned tool data overrides the agent's plan and redirects its actions.",
      "detection_surface": [
        "content",
        "tool_response"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI01"
        ],
        "mitre_atlas": [
          "AML.T0051.001",
          "AML.T0099"
        ],
        "cwe": [
          "CWE-1427"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://arxiv.org/abs/2403.02691"
        }
      ],
      "atr_rule": "ATR-2026-00584"
    },
    {
      "atd_id": "ATD-T0013",
      "schema_version": "0.1.0",
      "title": "System-prompt / guardrail extraction to plan evasion",
      "tactic": "ATD-TA3",
      "abstraction": "base",
      "status": "experimental",
      "severity": "medium",
      "description": "Crafted queries coerce the agent to reveal its hidden system prompt, exposing control logic.",
      "detection_surface": [
        "content",
        "tool_response"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI01",
          "ASI09"
        ],
        "mitre_atlas": [
          "AML.T0056"
        ],
        "cwe": [
          "CWE-200"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://atlas.mitre.org/"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25475"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-26326"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-41124"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39889"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45387"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-49988"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45351"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55837"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-6984"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44479"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40151"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54264"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41182"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46406"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46443"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46726"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47165"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55993"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55994"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59222"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47644"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50519"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54130"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14898"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-2589"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-29787"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-29872"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32625"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40159"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42456"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43992"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53923"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54316"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56259"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55608"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59216"
        }
      ]
    },
    {
      "atd_id": "ATD-T0014",
      "schema_version": "0.1.0",
      "title": "Confused-deputy token passthrough in an MCP server",
      "tactic": "ATD-TA4",
      "abstraction": "base",
      "status": "experimental",
      "severity": "high",
      "description": "A server forwards a held token to a downstream API without audience validation, escalating privilege.",
      "detection_surface": [
        "tool_input"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI03"
        ],
        "mitre_atlas": [],
        "cwe": [
          "CWE-441"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://modelcontextprotocol.io/specification/2025-11-25/basic/authorization"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27124"
        }
      ]
    },
    {
      "atd_id": "ATD-T0015",
      "schema_version": "0.1.0",
      "title": "Agent reads .env / secret files without consent",
      "tactic": "ATD-TA5",
      "abstraction": "base",
      "status": "experimental",
      "severity": "high",
      "description": "An agent tool reads credential files (.env, credentials, .npmrc) outside any user-approved scope.",
      "detection_surface": [
        "tool_input",
        "tool_response"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI02",
          "ASI06"
        ],
        "mitre_atlas": [
          "AML.T0053"
        ],
        "cwe": [
          "CWE-538"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://github.com/modelcontextprotocol-security/vulnerability-db"
        }
      ],
      "atr_rule": "ATR-2026-00583"
    },
    {
      "atd_id": "ATD-T0016",
      "schema_version": "0.1.0",
      "title": "Hallucinated-dependency squatting (slopsquatting)",
      "tactic": "ATD-TA5",
      "abstraction": "base",
      "status": "experimental",
      "severity": "medium",
      "description": "The model recommends a fabricated package name an attacker pre-registers, pulling code into the agent env.",
      "detection_surface": [
        "tool_input",
        "tool_response"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI04",
          "ASI08"
        ],
        "mitre_atlas": [
          "AML.T0060",
          "AML.T0062"
        ],
        "cwe": [
          "CWE-1427"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://atlas.mitre.org/"
        }
      ]
    },
    {
      "atd_id": "ATD-T0017",
      "schema_version": "0.1.0",
      "title": "Path-traversal blacklist bypass via non-canonical paths",
      "tactic": "ATD-TA6",
      "abstraction": "base",
      "status": "experimental",
      "severity": "medium",
      "description": "Exact-string path checks are bypassed with ../, /./, redundant slashes to reach sensitive files.",
      "detection_surface": [
        "tool_input",
        "trace"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI02",
          "ASI03"
        ],
        "mitre_atlas": [
          "AML.T0053"
        ],
        "cwe": [
          "CWE-22"
        ]
      },
      "references": [
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-66689"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27654"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7474"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10830"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32018"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-26321"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-26329"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-26972"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-23522"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-53951"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-54658"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34451"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40152"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47394"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50181"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-53110"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7774"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-35668"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47397"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43567"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50180"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7149"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41363"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34070"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3571"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-52830"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7212"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54352"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7159"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25640"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12243"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44024"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59221"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45482"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3234"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36420"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15138"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32719"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33989"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39861"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40576"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41863"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42078"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42080"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42249"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43901"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43989"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44336"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48789"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4944"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53766"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55443"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55607"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-57571"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58171"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59820"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-61445"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7020"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7272"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7318"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7384"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7445"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7594"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7599"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7645"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7715"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7728"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7738"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7788"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7811"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9467"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0129"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23250"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23304"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24147"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24208"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24209"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56260"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15749"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15751"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53598"
        }
      ],
      "atr_rule": "ATR-2026-00578"
    },
    {
      "atd_id": "ATD-T0018",
      "schema_version": "0.1.0",
      "title": "MCP filesystem sandbox escape via symlink following",
      "tactic": "ATD-TA6",
      "abstraction": "base",
      "status": "experimental",
      "severity": "high",
      "description": "A symlink inside an allowed directory resolves to an out-of-scope path, granting system file access.",
      "detection_surface": [
        "tool_input",
        "trace"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI02",
          "ASI05"
        ],
        "mitre_atlas": [
          "AML.T0053"
        ],
        "cwe": [
          "CWE-59"
        ]
      },
      "references": [
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-53109"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45539"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34452"
        }
      ]
    },
    {
      "atd_id": "ATD-T0019",
      "schema_version": "0.1.0",
      "title": "Prompt-injection-to-RCE via an agent's file-write capability",
      "tactic": "ATD-TA6",
      "abstraction": "base",
      "status": "experimental",
      "severity": "critical",
      "description": "Injected instructions drive the agent to write a startup/config file that yields persistent code execution.",
      "detection_surface": [
        "tool_input",
        "trace"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI05",
          "ASI01"
        ],
        "mitre_atlas": [
          "AML.T0053",
          "AML.T0051.001"
        ],
        "cwe": [
          "CWE-94"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://www.pillar.security/blog/prompt-injection-leads-to-rce-and-sandbox-escape-in-antigravity"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10950"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10954"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1550"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2867"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24764"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-39160"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-0845"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-22965"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36258"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39662"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47398"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36281"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4264"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38896"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21513"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41138"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39631"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38860"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29374"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45201"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5751"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36095"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4181"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54769"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-31233"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23731"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48519"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3098"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45311"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12252"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46442"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47162"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47167"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50223"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54133"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7873"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31621"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-58351"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61260"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-65719"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-10789"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-30306"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-30308"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-30741"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-31252"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33654"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33873"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41523"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44717"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45555"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46432"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4963"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53753"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-57572"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59821"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-61447"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7669"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23251"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23298"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23307"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23312"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23313"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23314"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23315"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23361"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33178"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33233"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33236"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33250"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33251"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24155"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-10875"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61590"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27966"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46633"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46640"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50510"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46512"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53597"
        }
      ]
    },
    {
      "atd_id": "ATD-T0020",
      "schema_version": "0.1.0",
      "title": "Agent Card poisoning to capture A2A task routing",
      "tactic": "ATD-TA7",
      "abstraction": "base",
      "status": "experimental",
      "severity": "high",
      "description": "A rogue A2A agent advertises an instruction-laden Agent Card so the orchestrator routes tasks to it.",
      "detection_surface": [
        "inter_agent_msg"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI07",
          "ASI10"
        ],
        "mitre_atlas": [
          "AML.T0051.001"
        ],
        "cwe": [
          "CWE-345"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://www.levelblue.com/blogs/spiderlabs-blog/agent-in-the-middle-abusing-agent-cards-in-the-agent-2-agent-protocol-to-win-all-the-tasks"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1945"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-26327"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-41087"
        }
      ]
    },
    {
      "atd_id": "ATD-T0021",
      "schema_version": "0.1.0",
      "title": "Cross-agent injection propagation (cascading compromise)",
      "tactic": "ATD-TA7",
      "abstraction": "base",
      "status": "experimental",
      "severity": "high",
      "description": "One compromised agent emits content that injects the next downstream agent, cascading through the swarm.",
      "detection_surface": [
        "inter_agent_msg"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI08",
          "ASI07",
          "ASI10"
        ],
        "mitre_atlas": [
          "AML.T0051.001",
          "AML.T0080"
        ],
        "cwe": [
          "CWE-1427"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://arxiv.org/abs/2403.02691"
        }
      ]
    },
    {
      "atd_id": "ATD-T0022",
      "schema_version": "0.1.0",
      "title": "Trace tampering / non-tamper-evident agent audit logs",
      "tactic": "ATD-TA8",
      "abstraction": "base",
      "status": "experimental",
      "severity": "medium",
      "description": "An agent logs reasoning but not the actual tool call, or logs are mutable — defeating after-the-fact audit.",
      "detection_surface": [
        "trace"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI10"
        ],
        "mitre_atlas": [],
        "cwe": [
          "CWE-778"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://artificialintelligenceact.eu/article/12/"
        }
      ]
    },
    {
      "atd_id": "ATD-T0023",
      "schema_version": "0.1.0",
      "title": "Adversarial transaction steering of a purchasing agent",
      "tactic": "ATD-TA9",
      "abstraction": "base",
      "status": "experimental",
      "severity": "medium",
      "description": "Injected content in a listing/page steers an autonomous-commerce agent to overpay or leak payment authority.",
      "detection_surface": [
        "payment_mandate"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI01",
          "ASI02",
          "ASI09"
        ],
        "mitre_atlas": [],
        "cwe": [
          "CWE-1427"
        ]
      },
      "references": [
        {
          "type": "vendor",
          "url": "https://cloud.google.com/blog/products/ai-machine-learning/announcing-agents-to-payments-ap2-protocol"
        }
      ]
    },
    {
      "atd_id": "ATD-T0024",
      "schema_version": "0.1.0",
      "title": "Payment-mandate forgery in an agent-to-agent handshake",
      "tactic": "ATD-TA9",
      "abstraction": "base",
      "status": "experimental",
      "severity": "medium",
      "description": "A rogue agent spoofs delegated payment authority or mandate scope in an agentic-commerce exchange.",
      "detection_surface": [
        "payment_mandate"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI03",
          "ASI07"
        ],
        "mitre_atlas": [],
        "cwe": [
          "CWE-345"
        ]
      },
      "references": [
        {
          "type": "vendor",
          "url": "https://fidoalliance.org/fido-alliance-to-develop-standards-for-trusted-ai-agent-interactions/"
        }
      ]
    },
    {
      "atd_id": "ATD-T0026",
      "schema_version": "0.1.0",
      "title": "Sleeper (dormant) memory poisoning",
      "tactic": "ATD-TA2",
      "abstraction": "base",
      "status": "experimental",
      "severity": "high",
      "description": "Attacker-controlled external content is written into the agent's persistent memory and lies dormant across sessions, re-emerging in later conversations to steer actions — decoupling the injection event from the malicious effect in time. The deterministic detection chokepoint is the memory-write boundary.",
      "detection_surface": [
        "memory_op"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI06"
        ],
        "mitre_atlas": [
          "AML.T0080"
        ],
        "cwe": [
          "CWE-349"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://arxiv.org/abs/2605.15338"
        }
      ]
    },
    {
      "atd_id": "ATD-T0025",
      "schema_version": "0.1.0",
      "title": "Acoustic prompt injection of a voice agent",
      "tactic": "ATD-TA8",
      "abstraction": "base",
      "status": "experimental",
      "severity": "high",
      "description": "An imperceptible adversarial audio perturbation mixed into normal speech drives a voice / audio-LLM agent to issue real tool calls, under audio-data-only access and with no textual user instruction. Text-layer rules cannot see it; detection is limited to the trace plane (a voice-initiated session producing high-risk tool calls with no corresponding textual instruction).",
      "detection_surface": [
        "trace"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI01"
        ],
        "mitre_atlas": [],
        "cwe": [
          "CWE-1427"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://arxiv.org/abs/2604.14604"
        }
      ]
    },
    {
      "atd_id": "ATD-T0027",
      "schema_version": "0.1.0",
      "title": "Persona/roleplay jailbreak to override safety policy",
      "tactic": "ATD-TA3",
      "abstraction": "base",
      "status": "experimental",
      "severity": "high",
      "description": "Attacker assigns the model an unrestricted alter-ego or fictional character (DAN, AIM, Developer Mode, dual-response split, grandma/historical/amoral persona, game-master) so it treats safety-violating output as in-character roleplay rather than its own refusal-bound behavior.",
      "detection_surface": [
        "content"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI01"
        ],
        "mitre_atlas": [
          "AML.T0054",
          "AML.T0051.000"
        ],
        "cwe": [
          "CWE-1427"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://github.com/Agent-Threat-Rule/agent-threat-rules"
        }
      ],
      "atr_rule": "ATR-2026-00457"
    },
    {
      "atd_id": "ATD-T0028",
      "schema_version": "0.1.0",
      "title": "Direct instruction override and goal hijacking",
      "tactic": "ATD-TA3",
      "abstraction": "base",
      "status": "experimental",
      "severity": "critical",
      "description": "Untrusted input issues imperative directives (ignore/forget previous instructions, redefine the system prompt, force verbatim payload output) or pivots the objective via false premise / goal drift, displacing the agent's assigned goal and constraints without persona framing.",
      "detection_surface": [
        "content"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI01"
        ],
        "mitre_atlas": [
          "AML.T0051",
          "AML.T0051.000"
        ],
        "cwe": [
          "CWE-1427"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5184"
        }
      ],
      "atr_rule": "ATR-2026-00004"
    },
    {
      "atd_id": "ATD-T0029",
      "schema_version": "0.1.0",
      "title": "Encoding/cipher obfuscation to smuggle harmful instructions past plaintext filters",
      "tactic": "ATD-TA3",
      "abstraction": "base",
      "status": "experimental",
      "severity": "high",
      "description": "Harmful instructions are wrapped in a reversible visible encoding (Base16/32/64/85, hex, Morse, NATO, leetspeak, Braille, Ecoji, Base2048, ROT/cipher, homoglyph) and the model is asked to decode-then-execute, exploiting that plaintext-trained safety classifiers do not generalize to the encoded form.",
      "detection_surface": [
        "content"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI01"
        ],
        "mitre_atlas": [
          "AML.T0054",
          "AML.T0051",
          "AML.T0068"
        ],
        "cwe": [
          "CWE-1427"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://github.com/Agent-Threat-Rule/agent-threat-rules"
        }
      ],
      "atr_rule": "ATR-2026-00256"
    },
    {
      "atd_id": "ATD-T0030",
      "schema_version": "0.1.0",
      "title": "Invisible Unicode steganographic smuggling of agent instructions",
      "tactic": "ATD-TA3",
      "abstraction": "base",
      "status": "experimental",
      "severity": "high",
      "description": "Instructions are hidden in imperceptible Unicode that renders blank to humans but tokenizes for the model: zero-width chars, BiDi RLO/LRO overrides, Unicode Tag-block (U+E0000-E007F), variation-selector ASCII smuggling, breaking keyword matching and human audit while preserving model comprehension.",
      "detection_surface": [
        "content"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI01"
        ],
        "mitre_atlas": [
          "AML.T0051"
        ],
        "cwe": [
          "CWE-1427"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://github.com/Agent-Threat-Rule/agent-threat-rules"
        }
      ],
      "atr_rule": "ATR-2026-00276"
    },
    {
      "atd_id": "ATD-T0031",
      "schema_version": "0.1.0",
      "title": "Hypothetical/fictional/tense reframing to bypass refusal",
      "tactic": "ATD-TA3",
      "abstraction": "base",
      "status": "experimental",
      "severity": "high",
      "description": "The harmful request is wrapped in a distancing frame — fictional/story/academic context, past/future tense rewrite, hypothetical-response or function-masking continuation — so the model answers the harmful core believing it is producing fiction or historical analysis.",
      "detection_surface": [
        "content"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI01"
        ],
        "mitre_atlas": [
          "AML.T0054"
        ],
        "cwe": [
          "CWE-1427"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://github.com/Agent-Threat-Rule/agent-threat-rules"
        }
      ],
      "atr_rule": "ATR-2026-00409"
    },
    {
      "atd_id": "ATD-T0032",
      "schema_version": "0.1.0",
      "title": "Coercive output-format and conditional-unlock pressure",
      "tactic": "ATD-TA3",
      "abstraction": "base",
      "status": "experimental",
      "severity": "medium",
      "description": "The prompt applies threats, ultimatums, or fabricated conditional-unlock rules to force the model into an attacker-specified output mode or override its formatting/refusal policy.",
      "detection_surface": [
        "content"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI01"
        ],
        "mitre_atlas": [
          "AML.T0051",
          "AML.T0054"
        ],
        "cwe": []
      },
      "references": [
        {
          "type": "research",
          "url": "https://github.com/Agent-Threat-Rule/agent-threat-rules"
        }
      ],
      "atr_rule": "ATR-2026-00287"
    },
    {
      "atd_id": "ATD-T0033",
      "schema_version": "0.1.0",
      "title": "Casual-authority impersonation for scope escalation and output redirect",
      "tactic": "ATD-TA3",
      "abstraction": "base",
      "status": "experimental",
      "severity": "critical",
      "description": "Conversational, informal authority claims (\"the orchestrator wants...\", \"the boss said skip...\") assert delegated permission to widen the agent's scope, disable safety filters, or redirect output to an attacker endpoint, evading explicit-injection detection.",
      "detection_surface": [
        "content"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI01",
          "ASI10"
        ],
        "mitre_atlas": [
          "AML.T0051"
        ],
        "cwe": []
      },
      "references": [
        {
          "type": "research",
          "url": "https://github.com/Agent-Threat-Rule/agent-threat-rules"
        }
      ],
      "atr_rule": "ATR-2026-00132"
    },
    {
      "atd_id": "ATD-T0034",
      "schema_version": "0.1.0",
      "title": "Foot-in-the-door gradual compliance escalation",
      "tactic": "ATD-TA3",
      "abstraction": "base",
      "status": "experimental",
      "severity": "high",
      "description": "The attacker establishes compliance with a benign request, then incrementally escalates toward harmful instructions while citing the agent's prior compliance as justification.",
      "detection_surface": [
        "content"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI01"
        ],
        "mitre_atlas": [
          "AML.T0051"
        ],
        "cwe": []
      },
      "references": [
        {
          "type": "research",
          "url": "https://github.com/Agent-Threat-Rule/agent-threat-rules"
        }
      ],
      "atr_rule": "ATR-2026-00269"
    },
    {
      "atd_id": "ATD-T0035",
      "schema_version": "0.1.0",
      "title": "Token-level adversarial suffix and special-token boundary injection",
      "tactic": "ATD-TA8",
      "abstraction": "base",
      "status": "experimental",
      "severity": "high",
      "description": "Model-intrinsic exploitation: gradient-optimized suffixes (GCG bracket/word-salad) or model-specific control tokens (<|endoftext|>, ChatML <|im_start|>system, glitch tokens) are appended to shift output toward compliance or reset safety context with no semantic framing.",
      "detection_surface": [
        "content"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI01"
        ],
        "mitre_atlas": [
          "AML.T0054",
          "AML.T0051"
        ],
        "cwe": [
          "CWE-1427"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://github.com/Agent-Threat-Rule/agent-threat-rules"
        }
      ],
      "atr_rule": "ATR-2026-00267"
    },
    {
      "atd_id": "ATD-T0036",
      "schema_version": "0.1.0",
      "title": "Output-boundary bypass to elicit harmful or prohibited content",
      "tactic": "ATD-TA8",
      "abstraction": "base",
      "status": "experimental",
      "severity": "high",
      "description": "An attacker shapes the request — completion-baiting, structured harm solicitation, or vulnerable-population framing — so the model emits content it would refuse if asked directly.",
      "detection_surface": [
        "content"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI01"
        ],
        "mitre_atlas": [
          "AML.T0054",
          "AML.T0057"
        ],
        "cwe": [
          "CWE-1427"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://github.com/Agent-Threat-Rule/agent-threat-rules"
        }
      ],
      "atr_rule": "ATR-2026-00279"
    },
    {
      "atd_id": "ATD-T0037",
      "schema_version": "0.1.0",
      "title": "Coercing the model to generate weaponized or scanner-evading output",
      "tactic": "ATD-TA8",
      "abstraction": "base",
      "status": "experimental",
      "severity": "critical",
      "description": "The model is directed to produce operational malicious artifacts (malware code, sub-functions) or known-bad test signatures (EICAR/GTUBE) that probe whether the output pipeline has any AV/scanning layer.",
      "detection_surface": [
        "content"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI01",
          "ASI08"
        ],
        "mitre_atlas": [
          "AML.T0053"
        ],
        "cwe": []
      },
      "references": [
        {
          "type": "research",
          "url": "https://github.com/Agent-Threat-Rule/agent-threat-rules"
        }
      ],
      "atr_rule": "ATR-2026-00413"
    },
    {
      "atd_id": "ATD-T0038",
      "schema_version": "0.1.0",
      "title": "Model IP and training-data extraction via systematic inference probing",
      "tactic": "ATD-TA8",
      "abstraction": "base",
      "status": "experimental",
      "severity": "medium",
      "description": "An attacker issues bulk or divergent-repetition queries against the inference API to recover memorized training data or distill the model's behavior into a functional clone.",
      "detection_surface": [
        "content"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI01"
        ],
        "mitre_atlas": [
          "AML.T0040",
          "AML.T0024"
        ],
        "cwe": [
          "CWE-200"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://github.com/Agent-Threat-Rule/agent-threat-rules"
        }
      ],
      "atr_rule": "ATR-2026-00502"
    },
    {
      "atd_id": "ATD-T0039",
      "schema_version": "0.1.0",
      "title": "Human-in-the-loop trust and approval-fatigue exploitation",
      "tactic": "ATD-TA6",
      "abstraction": "base",
      "status": "experimental",
      "severity": "high",
      "description": "Agent output is weaponized against the supervising human via fabricated confidence, suppressed uncertainty, manufactured urgency, or risky actions batched among benign ones to fatigue and bypass human approval gates.",
      "detection_surface": [
        "tool_input",
        "trace"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI09"
        ],
        "mitre_atlas": [],
        "cwe": []
      },
      "references": [
        {
          "type": "research",
          "url": "https://github.com/Agent-Threat-Rule/agent-threat-rules"
        }
      ],
      "atr_rule": "ATR-2026-00077"
    },
    {
      "atd_id": "ATD-T0040",
      "schema_version": "0.1.0",
      "title": "Agent rationalizes bypassing a required human-approval or safety gate",
      "tactic": "ATD-TA6",
      "abstraction": "base",
      "status": "experimental",
      "severity": "high",
      "description": "The agent skips a mandated approval/safety control — invoking a destructive tool with no preceding human-approval span, or self-justifying a direct path ('to be more efficient') — collapsing the human-in-the-loop checkpoint.",
      "detection_surface": [
        "tool_input",
        "trace"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI04",
          "ASI05"
        ],
        "mitre_atlas": [
          "AML.T0053"
        ],
        "cwe": [
          "CWE-862",
          "CWE-841"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://github.com/Agent-Threat-Rule/agent-threat-rules"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10274"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10330"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10762"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12606"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8999"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9000"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21396"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27484"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4888"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45350"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44554"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42436"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48797"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44562"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44563"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42851"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54329"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55432"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55433"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59217"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59225"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59226"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59227"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-31942"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40117"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40775"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41349"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45001"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46444"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-49948"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53818"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53820"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54842"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55638"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-57300"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-57922"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58168"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54695"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-62186"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46515"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-52870"
        }
      ],
      "atr_rule": "ATR-2026-00549"
    },
    {
      "atd_id": "ATD-T0041",
      "schema_version": "0.1.0",
      "title": "Agent code-execution sandbox escape achieves host RCE or boot-time persistence",
      "tactic": "ATD-TA6",
      "abstraction": "base",
      "status": "experimental",
      "severity": "critical",
      "description": "An agent's code-interpreter or VM sandbox is broken out of — via arbitrary file write to a startup path, eval/dynamic-import primitives, or a boundary flaw — yielding host code execution that can persist across restarts.",
      "detection_surface": [
        "tool_input",
        "trace"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI05",
          "ASI06"
        ],
        "mitre_atlas": [
          "AML.T0050"
        ],
        "cwe": [
          "CWE-94",
          "CWE-693"
        ]
      },
      "references": [
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27597"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47392"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34938"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27893"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59207"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-60086"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39888"
        }
      ],
      "atr_rule": "ATR-2026-00436"
    },
    {
      "atd_id": "ATD-T0042",
      "schema_version": "0.1.0",
      "title": "Consequential autonomous action without human-in-the-loop confirmation",
      "tactic": "ATD-TA6",
      "abstraction": "base",
      "status": "experimental",
      "severity": "critical",
      "description": "An agent executes a high-risk, often irreversible operation — payment/transfer, shell command, destructive call, internal-network fetch — without an explicit per-turn human approval gate.",
      "detection_surface": [
        "tool_input",
        "trace"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI07",
          "ASI06"
        ],
        "mitre_atlas": [
          "AML.T0053",
          "AML.T0101"
        ],
        "cwe": [
          "CWE-862"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://github.com/Agent-Threat-Rule/agent-threat-rules"
        }
      ],
      "atr_rule": "ATR-2026-00098"
    },
    {
      "atd_id": "ATD-T0043",
      "schema_version": "0.1.0",
      "title": "Runaway self-perpetuating execution loop (denial-of-wallet)",
      "tactic": "ATD-TA6",
      "abstraction": "base",
      "status": "experimental",
      "severity": "high",
      "description": "An agent enters an unbounded retry, recursive self-invocation, or tight tool-call loop with no termination condition, exhausting compute, budget, or downstream services.",
      "detection_surface": [
        "tool_input",
        "trace"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI07"
        ],
        "mitre_atlas": [
          "AML.T0034",
          "AML.T0046"
        ],
        "cwe": [
          "CWE-835"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://atlas.mitre.org/techniques/AML.T0034"
        }
      ],
      "atr_rule": "ATR-2026-00050"
    },
    {
      "atd_id": "ATD-T0044",
      "schema_version": "0.1.0",
      "title": "Inter-agent identity spoofing and forged-message injection",
      "tactic": "ATD-TA7",
      "abstraction": "base",
      "status": "experimental",
      "severity": "critical",
      "description": "A compromised or peer agent spoofs another agent's identity, forges system-level message tags, or injects unauthenticated A2A messages to exploit inter-agent trust for privilege escalation or orchestrator bypass.",
      "detection_surface": [
        "inter_agent_msg"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI07",
          "ASI10"
        ],
        "mitre_atlas": [
          "AML.T0051.001",
          "AML.T0051"
        ],
        "cwe": []
      },
      "references": [
        {
          "type": "research",
          "url": "https://github.com/Agent-Threat-Rule/agent-threat-rules"
        }
      ],
      "atr_rule": "ATR-2026-00030"
    },
    {
      "atd_id": "ATD-T0045",
      "schema_version": "0.1.0",
      "title": "Multi-agent consensus and Sybil manipulation",
      "tactic": "ATD-TA7",
      "abstraction": "base",
      "status": "experimental",
      "severity": "critical",
      "description": "Instructions spin up multiple fake agent identities to coordinate votes, flood false proposals, or overwhelm a multi-agent consensus or voting mechanism toward an attacker-chosen outcome.",
      "detection_surface": [
        "inter_agent_msg"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI10",
          "ASI07"
        ],
        "mitre_atlas": [
          "AML.T0043"
        ],
        "cwe": []
      },
      "references": [
        {
          "type": "research",
          "url": "https://github.com/Agent-Threat-Rule/agent-threat-rules"
        }
      ],
      "atr_rule": "ATR-2026-00108"
    },
    {
      "atd_id": "ATD-T0046",
      "schema_version": "0.1.0",
      "title": "Hidden directive embedded in MCP tool description subverts consent or safety gating",
      "tactic": "ATD-TA5",
      "abstraction": "base",
      "status": "experimental",
      "severity": "high",
      "description": "A tool's natural-language description or docstring carries imperative instructions (auto-forward results, skip user confirmation, ignore safety policy) that the model obeys at invocation time.",
      "detection_surface": [
        "tool_input",
        "tool_response"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI04",
          "ASI02"
        ],
        "mitre_atlas": [
          "AML.T0053"
        ],
        "cwe": [
          "CWE-94",
          "CWE-1427"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://github.com/Agent-Threat-Rule/agent-threat-rules"
        }
      ],
      "atr_rule": "ATR-2026-00100"
    },
    {
      "atd_id": "ATD-T0047",
      "schema_version": "0.1.0",
      "title": "Tool schema-description divergence hides write or admin capability behind a read-only claim",
      "tactic": "ATD-TA5",
      "abstraction": "base",
      "status": "experimental",
      "severity": "high",
      "description": "A tool advertises safe/read-only behavior in its description while its JSON schema or runtime accepts undeclared write-capable, admin, or debug parameters that exceed the stated function.",
      "detection_surface": [
        "tool_input",
        "tool_response"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI02",
          "ASI05"
        ],
        "mitre_atlas": [
          "AML.T0010",
          "AML.T0056"
        ],
        "cwe": [
          "CWE-1427",
          "CWE-440"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://github.com/Agent-Threat-Rule/agent-threat-rules"
        }
      ],
      "atr_rule": "ATR-2026-00106"
    },
    {
      "atd_id": "ATD-T0048",
      "schema_version": "0.1.0",
      "title": "Unauthenticated MCP server or agent API exposes privileged operations",
      "tactic": "ATD-TA5",
      "abstraction": "base",
      "status": "experimental",
      "severity": "critical",
      "description": "An MCP server, agent control API, or admin endpoint ships with authentication disabled or missing on critical functions, letting an unauthenticated caller invoke tools, exfiltrate data, or take over the cluster.",
      "detection_surface": [
        "tool_input",
        "tool_response"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI05",
          "ASI03"
        ],
        "mitre_atlas": [
          "AML.T0049",
          "AML.T0040"
        ],
        "cwe": [
          "CWE-306"
        ]
      },
      "references": [
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32211"
        }
      ],
      "atr_rule": "ATR-2026-00435"
    },
    {
      "atd_id": "ATD-T0049",
      "schema_version": "0.1.0",
      "title": "Untrusted tool output rendered without sanitization triggers terminal or browser code execution",
      "tactic": "ATD-TA5",
      "abstraction": "base",
      "status": "experimental",
      "severity": "high",
      "description": "Tool/skill output containing ANSI/OSC escape sequences or XSS payloads is passed unsanitized into a CLI terminal or web agent UI, hijacking the display, forging prompts, or executing script in the operator's session.",
      "detection_surface": [
        "tool_input",
        "tool_response"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI08",
          "ASI02"
        ],
        "mitre_atlas": [
          "AML.T0057",
          "AML.T0077"
        ],
        "cwe": [
          "CWE-150",
          "CWE-79"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://github.com/Agent-Threat-Rule/agent-threat-rules"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49785"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27009"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-32797"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-44163"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-45229"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54302"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54326"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58444"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-62800"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-31981"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34033"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46609"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53441"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54057"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55437"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59214"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59794"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59929"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32207"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49785"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-21866"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27740"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32112"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32626"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39426"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40112"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41318"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42045"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42138"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42235"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44429"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55481"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59795"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58500"
        }
      ],
      "atr_rule": "ATR-2026-00259"
    },
    {
      "atd_id": "ATD-T0050",
      "schema_version": "0.1.0",
      "title": "Agent SSRF via unvalidated fetch URL reaches cloud metadata or internal services",
      "tactic": "ATD-TA5",
      "abstraction": "base",
      "status": "experimental",
      "severity": "high",
      "description": "An agent fetch/RAG/retrieval tool accepts an attacker-influenced URL whose validator can be bypassed (encoding, decimal/hex IP, IPv6 loopback, DNS rebinding) to reach link-local cloud-metadata endpoints or internal hosts.",
      "detection_surface": [
        "tool_input",
        "tool_response"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI02",
          "ASI05"
        ],
        "mitre_atlas": [
          "AML.T0049"
        ],
        "cwe": [
          "CWE-918",
          "CWE-552"
        ]
      },
      "references": [
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-2286"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46348"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12779"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-26322"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-26324"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27488"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-21697"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-26013"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25580"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44661"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34954"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46229"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6604"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50143"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32786"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41271"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6605"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45310"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-49856"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48782"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46678"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5832"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6606"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6587"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53509"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-26019"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2828"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0243"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27795"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-49857"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3095"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32236"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45366"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25528"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34936"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-13773"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53827"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32964"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54157"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-66389"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-10280"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-10564"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12774"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12798"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14748"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15189"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15501"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25960"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-26118"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28451"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-30247"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-30858"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-31945"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32111"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32871"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33060"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34163"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34476"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34753"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39885"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39974"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40150"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40160"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41481"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41488"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42260"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42449"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4339"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43995"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44284"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44428"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44430"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44694"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45401"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45499"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45609"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5323"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53754"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53755"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54033"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5470"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55641"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5607"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56676"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-57573"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7146"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7147"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7150"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7158"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7221"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7417"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7729"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7817"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33203"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24231"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-56520"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15643"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15746"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15750"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-62240"
        }
      ],
      "atr_rule": "ATR-2026-00013"
    },
    {
      "atd_id": "ATD-T0051",
      "schema_version": "0.1.0",
      "title": "Malicious code execution staged inside an installed skill package",
      "tactic": "ATD-TA5",
      "abstraction": "base",
      "status": "experimental",
      "severity": "critical",
      "description": "A SKILL.md or bundled script carries executable attack payloads — base64/raw-IP droppers, reverse shells, fake-backup credential stealers, or C2 callbacks — that run when the skill is installed or invoked.",
      "detection_surface": [
        "tool_input",
        "tool_response"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI04"
        ],
        "mitre_atlas": [
          "AML.T0010"
        ],
        "cwe": [
          "CWE-506"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://github.com/Agent-Threat-Rule/agent-threat-rules"
        }
      ],
      "atr_rule": "ATR-2026-00121"
    },
    {
      "atd_id": "ATD-T0052",
      "schema_version": "0.1.0",
      "title": "Skill instruction smuggling via hidden/invisible payload channels",
      "tactic": "ATD-TA5",
      "abstraction": "base",
      "status": "experimental",
      "severity": "critical",
      "description": "Attack instructions are concealed in a skill's text where a human reviewer cannot see them — HTML comments, Unicode Tag characters (U+E0000 range), or other invisible glyphs — but the agent still parses and obeys them.",
      "detection_surface": [
        "tool_input",
        "tool_response"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI04"
        ],
        "mitre_atlas": [
          "AML.T0010"
        ],
        "cwe": [
          "CWE-506"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://github.com/Agent-Threat-Rule/agent-threat-rules"
        }
      ],
      "atr_rule": "ATR-2026-00128"
    },
    {
      "atd_id": "ATD-T0053",
      "schema_version": "0.1.0",
      "title": "Skill supply-chain tampering: rug-pull, time-bomb, and self-modifying persistence",
      "tactic": "ATD-TA5",
      "abstraction": "base",
      "status": "experimental",
      "severity": "critical",
      "description": "A skill is architected to mutate after trust is granted — remote dynamic-code loading, time-gated exfiltration triggers, post-install hooks, self-rewriting SKILL.md, or worm-style propagation — so benign-at-review content turns malicious at runtime.",
      "detection_surface": [
        "tool_input",
        "tool_response"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI04"
        ],
        "mitre_atlas": [
          "AML.T0010"
        ],
        "cwe": [
          "CWE-494"
        ]
      },
      "references": [
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-59536"
        }
      ],
      "atr_rule": "ATR-2026-00126"
    },
    {
      "atd_id": "ATD-T0054",
      "schema_version": "0.1.0",
      "title": "Upstream-skill impersonation: typosquat, fork-claim, and slopsquat baiting",
      "tactic": "ATD-TA5",
      "abstraction": "base",
      "status": "experimental",
      "severity": "high",
      "description": "A malicious package masquerades as a trusted tool via misspelled/namespace-colliding names, false 'community fork / enhanced version' install instructions, or hallucinated-dependency baiting, hijacking the trust of the legitimate upstream.",
      "detection_surface": [
        "tool_input",
        "tool_response"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI04"
        ],
        "mitre_atlas": [
          "AML.T0010"
        ],
        "cwe": [
          "CWE-829"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://github.com/Agent-Threat-Rule/agent-threat-rules"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-49986"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58116"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44995"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5241"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5817"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6859"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33205"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61592"
        }
      ],
      "atr_rule": "ATR-2026-00151"
    },
    {
      "atd_id": "ATD-T0055",
      "schema_version": "0.1.0",
      "title": "Weaponized skill turning the agent into an offensive/over-privileged actor",
      "tactic": "ATD-TA5",
      "abstraction": "base",
      "status": "experimental",
      "severity": "high",
      "description": "An approved skill exploits the post-consent gap to direct the agent itself into offensive operations or excessive scope — running attacker tooling, installing unauthorized background tasks, or loading unsafe model artifacts — beyond what the user sanctioned.",
      "detection_surface": [
        "tool_input",
        "tool_response"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI04"
        ],
        "mitre_atlas": [],
        "cwe": [
          "CWE-269"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://github.com/Agent-Threat-Rule/agent-threat-rules"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8719"
        }
      ],
      "atr_rule": "ATR-2026-00122"
    },
    {
      "atd_id": "ATD-T0056",
      "schema_version": "0.1.0",
      "title": "Agent tool exceeds delegated permission scope to reach admin or out-of-bounds functions",
      "tactic": "ATD-TA4",
      "abstraction": "base",
      "status": "experimental",
      "severity": "high",
      "description": "An agent invokes tools or administrative functions beyond its granted authority — abruptly or via incremental scope creep — accessing user-management, system-settings, or admin panels it was never delegated.",
      "detection_surface": [
        "tool_input",
        "trace"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI03"
        ],
        "mitre_atlas": [
          "AML.T0040",
          "AML.T0047"
        ],
        "cwe": [
          "CWE-269",
          "CWE-862"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://github.com/Agent-Threat-Rule/agent-threat-rules"
        }
      ],
      "atr_rule": "ATR-2026-00040"
    },
    {
      "atd_id": "ATD-T0057",
      "schema_version": "0.1.0",
      "title": "Credential/secret file harvest combined with network exfiltration",
      "tactic": "ATD-TA4",
      "abstraction": "base",
      "status": "experimental",
      "severity": "critical",
      "description": "Agent or MCP-tool instructions read well-known credential stores (.env, ~/.aws/credentials, SSH keys, .npmrc, browser cookie DBs) and pipe or POST them to an external endpoint in the same context, producing host credential theft with lateral-movement reach.",
      "detection_surface": [
        "tool_input",
        "trace"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI02",
          "ASI06"
        ],
        "mitre_atlas": [
          "AML.T0055",
          "AML.T0083",
          "AML.T0090",
          "AML.T0098"
        ],
        "cwe": [
          "CWE-522"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://github.com/Agent-Threat-Rule/agent-threat-rules"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48039"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53840"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-62208"
        }
      ],
      "atr_rule": "ATR-2026-00113"
    },
    {
      "atd_id": "ATD-T0058",
      "schema_version": "0.1.0",
      "title": "Agent memory or context store written across a conversation or tenant boundary",
      "tactic": "ATD-TA4",
      "abstraction": "base",
      "status": "experimental",
      "severity": "critical",
      "description": "An agent writes into a memory/vector store scoped to a different conversation or tenant than the active trace, escaping its data boundary to plant content that later sessions will read.",
      "detection_surface": [
        "tool_input",
        "trace"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI04",
          "ASI06"
        ],
        "mitre_atlas": [
          "AML.T0080"
        ],
        "cwe": [
          "CWE-668",
          "CWE-349"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://github.com/Agent-Threat-Rule/agent-threat-rules"
        }
      ],
      "atr_rule": "ATR-2026-00551"
    },
    {
      "atd_id": "ATD-T0059",
      "schema_version": "0.1.0",
      "title": "Sensitive data exfiltration via agent-rendered markdown image/link URL",
      "tactic": "ATD-TA2",
      "abstraction": "base",
      "status": "experimental",
      "severity": "high",
      "description": "The agent is coerced into emitting markdown image or link syntax whose attacker-controlled URL encodes conversation, secret, or context data, so the rendering client auto-fetches it and leaks the data out-of-band.",
      "detection_surface": [
        "memory_op",
        "content"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI06",
          "ASI08"
        ],
        "mitre_atlas": [
          "AML.T0024",
          "AML.T0057"
        ],
        "cwe": [
          "CWE-200"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://github.com/Agent-Threat-Rule/agent-threat-rules"
        }
      ],
      "atr_rule": "ATR-2026-00261"
    },
    {
      "atd_id": "ATD-T0060",
      "schema_version": "0.1.0",
      "title": "Tool-response-embedded exfiltration channel",
      "tactic": "ATD-TA2",
      "abstraction": "base",
      "status": "experimental",
      "severity": "critical",
      "description": "A tool or MCP response embeds a secret-harvesting instruction or sensitive-data addendum inside otherwise legitimate-looking output, exploiting the agent's trust in tool results to smuggle credentials or context into the next turn.",
      "detection_surface": [
        "memory_op",
        "content"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI06",
          "ASI08"
        ],
        "mitre_atlas": [
          "AML.T0054"
        ],
        "cwe": [
          "CWE-200"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://github.com/Agent-Threat-Rule/agent-threat-rules"
        }
      ],
      "atr_rule": "ATR-2026-00136"
    },
    {
      "atd_id": "ATD-T0061",
      "schema_version": "0.1.0",
      "title": "Credential elicitation in model output (secret completion / verbatim disclosure)",
      "tactic": "ATD-TA2",
      "abstraction": "base",
      "status": "experimental",
      "severity": "high",
      "description": "A prompt coaxes the model to generate, complete, partially reveal, or echo back live API keys, tokens, or secrets present in context (including obfuscated/encoded forms) so the secret materializes directly in the response.",
      "detection_surface": [
        "memory_op",
        "content"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI06"
        ],
        "mitre_atlas": [
          "AML.T0057"
        ],
        "cwe": [
          "CWE-200"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://github.com/Agent-Threat-Rule/agent-threat-rules"
        }
      ],
      "atr_rule": "ATR-2026-00021"
    },
    {
      "atd_id": "ATD-T0062",
      "schema_version": "0.1.0",
      "title": "Cross-context / cross-user memory leakage in multi-agent delegation",
      "tactic": "ATD-TA2",
      "abstraction": "base",
      "status": "experimental",
      "severity": "high",
      "description": "A privileged context attribute (session, user, or conversation id) fails to stay constant across an agent delegation chain or shared memory store, letting one user's or agent's context surface to another party.",
      "detection_surface": [
        "memory_op",
        "content"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI06"
        ],
        "mitre_atlas": [],
        "cwe": [
          "CWE-668"
        ]
      },
      "references": [
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41712"
        }
      ],
      "atr_rule": "ATR-2026-00548"
    },
    {
      "atd_id": "ATD-T0063",
      "schema_version": "0.1.0",
      "title": "Offline training / fine-tuning corpus contamination",
      "tactic": "ATD-TA2",
      "abstraction": "base",
      "status": "experimental",
      "severity": "high",
      "description": "An attacker plants malicious or label-flipped samples into a model's training or fine-tuning dataset so the deployed model carries an attacker-chosen behavior or backdoor.",
      "detection_surface": [
        "memory_op",
        "content"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI06"
        ],
        "mitre_atlas": [
          "AML.T0020",
          "AML.T0018"
        ],
        "cwe": [
          "CWE-349"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://atlas.mitre.org/techniques/AML.T0020"
        }
      ],
      "atr_rule": "ATR-2026-00073"
    },
    {
      "atd_id": "ATD-T0064",
      "schema_version": "0.1.0",
      "title": "Forged trusted-output-component manipulation",
      "tactic": "ATD-TA3",
      "abstraction": "base",
      "status": "experimental",
      "severity": "high",
      "description": "The agent emits output whose citations, source attributions, or structured 'verified' fields are attacker-forged, so a downstream consumer trusts fabricated components as authoritative.",
      "detection_surface": [
        "content"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI01",
          "ASI08"
        ],
        "mitre_atlas": [
          "AML.T0067"
        ],
        "cwe": [
          "CWE-345"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://atlas.mitre.org/techniques/AML.T0067"
        }
      ]
    },
    {
      "atd_id": "ATD-T0065",
      "schema_version": "0.1.0",
      "title": "Sensitive-data exfiltration via legitimate agent tool invocation",
      "tactic": "ATD-TA5",
      "abstraction": "base",
      "status": "experimental",
      "severity": "high",
      "description": "The agent invokes an otherwise-sanctioned tool (send, post, upload, write, fetch) to ship sensitive context or data to an attacker-controlled destination.",
      "detection_surface": [
        "tool_input",
        "tool_response"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI06",
          "ASI02"
        ],
        "mitre_atlas": [
          "AML.T0086"
        ],
        "cwe": [
          "CWE-200"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://atlas.mitre.org/techniques/AML.T0086"
        }
      ]
    },
    {
      "atd_id": "ATD-T0066",
      "schema_version": "0.1.0",
      "title": "Delayed or conditional execution of injected instructions",
      "tactic": "ATD-TA6",
      "abstraction": "base",
      "status": "experimental",
      "severity": "medium",
      "description": "An injected instruction defers its own effect to a later turn or a trigger condition so the malicious action fires after review rather than at ingestion time.",
      "detection_surface": [
        "tool_input",
        "trace"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI01",
          "ASI07"
        ],
        "mitre_atlas": [
          "AML.T0094"
        ],
        "cwe": [
          "CWE-506"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://atlas.mitre.org/techniques/AML.T0094"
        }
      ]
    },
    {
      "atd_id": "ATD-T0067",
      "schema_version": "0.1.0",
      "title": "Unauthenticated MCP transport endpoint exposed to network reach",
      "tactic": "ATD-TA1",
      "abstraction": "base",
      "status": "experimental",
      "severity": "high",
      "description": "An MCP server's SSE/HTTP transport port is bound to a routable interface with no auth, so a remote or cross-origin caller can open a session and invoke tools.",
      "detection_surface": [
        "tool_input",
        "tool_response"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI03",
          "ASI05"
        ],
        "mitre_atlas": [],
        "cwe": [
          "CWE-668"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://github.com/SAFE-MCP/safe-mcp/blob/main/techniques/SAFE-T1005/README.md"
        }
      ]
    },
    {
      "atd_id": "ATD-T0068",
      "schema_version": "0.1.0",
      "title": "OAuth consent phishing to bind an attacker-controlled MCP authorization grant",
      "tactic": "ATD-TA4",
      "abstraction": "base",
      "status": "experimental",
      "severity": "high",
      "description": "A user is steered through a real OAuth consent screen for an attacker's client/redirect so the agent ends up holding a token scoped to the attacker.",
      "detection_surface": [
        "tool_input",
        "trace"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI03"
        ],
        "mitre_atlas": [],
        "cwe": [
          "CWE-1021"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://github.com/SAFE-MCP/safe-mcp/blob/main/techniques/SAFE-T1007/README.md"
        }
      ]
    },
    {
      "atd_id": "ATD-T0069",
      "schema_version": "0.1.0",
      "title": "OAuth protocol downgrade to defeat PKCE or strip token binding",
      "tactic": "ATD-TA4",
      "abstraction": "base",
      "status": "experimental",
      "severity": "high",
      "description": "The MCP authorization handshake is forced onto a weaker flow (implicit grant, dropped PKCE/state) so an intercepted code or token can be replayed.",
      "detection_surface": [
        "tool_input",
        "trace"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI03"
        ],
        "mitre_atlas": [],
        "cwe": [
          "CWE-757"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://github.com/SAFE-MCP/safe-mcp/blob/main/techniques/SAFE-T1408/README.md"
        }
      ]
    },
    {
      "atd_id": "ATD-T0070",
      "schema_version": "0.1.0",
      "title": "Agent reads process environment variables to harvest injected secrets",
      "tactic": "ATD-TA4",
      "abstraction": "base",
      "status": "experimental",
      "severity": "high",
      "description": "An agent or MCP tool enumerates process env vars (printenv, process.env, os.environ) to lift API keys and tokens injected at server startup.",
      "detection_surface": [
        "tool_input",
        "trace"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI06"
        ],
        "mitre_atlas": [
          "AML.T0055"
        ],
        "cwe": [
          "CWE-526"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://github.com/SAFE-MCP/safe-mcp/blob/main/techniques/SAFE-T1503/README.md"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45370"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40153"
        }
      ]
    },
    {
      "atd_id": "ATD-T0071",
      "schema_version": "0.1.0",
      "title": "Cross-server tool-chaining pivot reaches an unrelated tool's resources",
      "tactic": "ATD-TA5",
      "abstraction": "base",
      "status": "experimental",
      "severity": "high",
      "description": "The agent is steered to pass one tool's output as another connected tool's input so a low-trust tool drives a high-privilege tool's action across server boundaries.",
      "detection_surface": [
        "tool_input",
        "tool_response"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI05",
          "ASI03"
        ],
        "mitre_atlas": [
          "AML.T0047"
        ],
        "cwe": [
          "CWE-441"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://github.com/SAFE-MCP/safe-mcp/blob/main/techniques/SAFE-T1703/README.md"
        }
      ]
    },
    {
      "atd_id": "ATD-T0072",
      "schema_version": "0.1.0",
      "title": "Outbound webhook used as covert command-and-control channel",
      "tactic": "ATD-TA5",
      "abstraction": "base",
      "status": "experimental",
      "severity": "high",
      "description": "An agent tool registers or polls an attacker-controlled webhook/URL, turning routine outbound HTTP into a tasking and data-return channel.",
      "detection_surface": [
        "tool_input",
        "tool_response"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI08",
          "ASI06"
        ],
        "mitre_atlas": [
          "AML.T0072"
        ],
        "cwe": [
          "CWE-918"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://github.com/SAFE-MCP/safe-mcp/blob/main/techniques/SAFE-T1901/README.md"
        }
      ]
    },
    {
      "atd_id": "ATD-T0073",
      "schema_version": "0.1.0",
      "title": "Agent model-output reconnaissance and guardrail fingerprinting",
      "tactic": "ATD-TA8",
      "abstraction": "base",
      "status": "experimental",
      "severity": "medium",
      "description": "An attacker systematically probes an agent's responses to fingerprint the underlying model, its guardrails, or its output format in order to tailor a follow-on attack.",
      "detection_surface": [
        "content"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI01"
        ],
        "mitre_atlas": [
          "AML.T0063"
        ],
        "cwe": [
          "CWE-200"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://atlas.mitre.org/techniques/AML.T0063"
        }
      ]
    },
    {
      "atd_id": "ATD-T0074",
      "schema_version": "0.1.0",
      "title": "RAG and retrieval-index target reconnaissance",
      "tactic": "ATD-TA2",
      "abstraction": "base",
      "status": "experimental",
      "severity": "medium",
      "description": "An attacker enumerates an agent's RAG or retrieval index to locate documents to poison or sensitive entries to exfiltrate.",
      "detection_surface": [
        "memory_op",
        "content"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI06"
        ],
        "mitre_atlas": [
          "AML.T0064"
        ],
        "cwe": [
          "CWE-200"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://atlas.mitre.org/techniques/AML.T0064"
        }
      ]
    },
    {
      "atd_id": "ATD-T0075",
      "schema_version": "0.1.0",
      "title": "Agent configuration and permission reconnaissance",
      "tactic": "ATD-TA4",
      "abstraction": "base",
      "status": "experimental",
      "severity": "medium",
      "description": "An attacker discovers an agent's configuration, connected tools, and granted permissions to plan a tailored privilege-escalation or tool-abuse attack.",
      "detection_surface": [
        "tool_input",
        "trace"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI03"
        ],
        "mitre_atlas": [
          "AML.T0084"
        ],
        "cwe": [
          "CWE-200"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://atlas.mitre.org/techniques/AML.T0084"
        }
      ]
    },
    {
      "atd_id": "ATD-T0076",
      "schema_version": "0.1.0",
      "title": "Fraudulent transaction execution by a compromised commerce agent",
      "tactic": "ATD-TA9",
      "abstraction": "base",
      "status": "experimental",
      "severity": "high",
      "description": "A compromised or manipulated purchasing or payment agent executes unauthorized or fraudulent transactions on the user's behalf.",
      "detection_surface": [
        "payment_mandate"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI06",
          "ASI01"
        ],
        "mitre_atlas": [],
        "cwe": [
          "CWE-840"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://github.com/SAFE-MCP/safe-mcp/blob/main/techniques/SAFE-T2104/README.md"
        }
      ]
    },
    {
      "atd_id": "ATD-T0077",
      "schema_version": "0.1.0",
      "title": "Broken object or workspace authorization in an agent tool (IDOR)",
      "tactic": "ATD-TA4",
      "abstraction": "base",
      "status": "experimental",
      "severity": "high",
      "description": "An agent or MCP tool serves or mutates data across a user, workspace, or tenant boundary because it omits object-level authorization, letting one principal reach another principal's resources.",
      "detection_surface": [
        "tool_input",
        "trace"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI03"
        ],
        "mitre_atlas": [],
        "cwe": [
          "CWE-639",
          "CWE-863",
          "CWE-284"
        ]
      },
      "references": [
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46519"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5199"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10109"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10273"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-26316"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-26328"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-36778"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33460"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-35029"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-69196"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34046"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47407"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46549"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5710"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-35653"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47388"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53835"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54765"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55428"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55435"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59212"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32174"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32213"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33102"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-35435"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41106"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47645"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-10277"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12797"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28361"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-30857"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32715"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32717"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33946"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34082"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34953"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-35402"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-35674"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44556"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44998"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45707"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47101"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47102"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48529"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5374"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5379"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5382"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54555"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55604"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7663"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2002-2036"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-24086"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54052"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-35210"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-35211"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-57215"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58617"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-52869"
        }
      ]
    },
    {
      "atd_id": "ATD-T0078",
      "schema_version": "0.1.0",
      "title": "Prompt-to-SQL injection via an agent's natural-language database tool",
      "tactic": "ATD-TA5",
      "abstraction": "base",
      "status": "experimental",
      "severity": "critical",
      "description": "An agent's database or query tool builds a SQL/query string from natural-language or model output without parameterization, so a crafted prompt injects the query and can escalate to RCE.",
      "detection_surface": [
        "tool_input",
        "tool_response"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI05",
          "ASI02"
        ],
        "mitre_atlas": [
          "AML.T0053"
        ],
        "cwe": [
          "CWE-89"
        ]
      },
      "references": [
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25879"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10835"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12909"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12911"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42208"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23751"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8309"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7042"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36189"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-10105"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32785"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4890"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5225"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1793"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47255"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11945"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3602"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-49498"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-52758"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56292"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59257"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-66336"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14471"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-30860"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32628"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33324"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-35228"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4593"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5322"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55405"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7591"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-35152"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45073"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56287"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-57821"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-62390"
        }
      ]
    },
    {
      "atd_id": "ATD-T0079",
      "schema_version": "0.1.0",
      "title": "Secret leakage through agent or MCP server logs and traces",
      "tactic": "ATD-TA8",
      "abstraction": "base",
      "status": "experimental",
      "severity": "high",
      "description": "An agent or MCP server writes tool arguments, queries, or responses containing credentials or secrets into logs or traces, exposing them to anyone with log or trace access.",
      "detection_surface": [
        "content"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI06"
        ],
        "mitre_atlas": [],
        "cwe": [
          "CWE-532"
        ]
      },
      "references": [
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44969"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-70040"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20205"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41495"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42282"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46514"
        }
      ]
    },
    {
      "atd_id": "ATD-T0080",
      "schema_version": "0.1.0",
      "title": "Cross-client data leak via shared MCP server state",
      "tactic": "ATD-TA1",
      "abstraction": "base",
      "status": "experimental",
      "severity": "high",
      "description": "A shared MCP server or transport mixes state across concurrent clients (a race condition or missing per-client isolation), so one client receives another client's data or context.",
      "detection_surface": [
        "tool_input",
        "tool_response"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI06",
          "ASI07"
        ],
        "mitre_atlas": [],
        "cwe": [
          "CWE-362"
        ]
      },
      "references": [
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25536"
        }
      ]
    },
    {
      "atd_id": "ATD-T0081",
      "schema_version": "0.1.0",
      "title": "Remediation-framed command execution via tool-response injection (agentjacking)",
      "tactic": "ATD-TA5",
      "abstraction": "base",
      "status": "experimental",
      "severity": "high",
      "description": "Externally-influenced content returned through an MCP/tool integration disguises an executable command as legitimate remediation guidance (a Resolution/recommended-fix/required-step section running an npx/uvx/pipx package or a pipe-to-shell one-liner), so an AI coding agent runs attacker-controlled code while every step in the chain appears authorized. Prompt-layer defenses fail because the agent cannot distinguish data it reads from an instruction to act; the durable mitigation is detection on the tool-output boundary. Generalizes beyond the disclosed Sentry vector to any tool integration that returns externally-influenced data to an agent.",
      "detection_surface": [
        "tool_response"
      ],
      "mappings": {
        "owasp_asi": [
          "ASI02",
          "ASI05"
        ],
        "mitre_atlas": [
          "AML.T0051.001"
        ],
        "cwe": [
          "CWE-829",
          "CWE-77"
        ]
      },
      "references": [
        {
          "type": "research",
          "url": "https://tenetsecurity.ai/blog/agentjacking-coding-agents-with-fake-sentry-errors/"
        },
        {
          "type": "research",
          "url": "https://labs.cloudsecurityalliance.org/research/csa-research-note-agentjacking-mcp-sentry-injection-20260612/"
        },
        {
          "type": "cve",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28260"
        }
      ],
      "atr_rule": "ATR-2026-02260"
    }
  ]
}
