THREAT COVERAGE STARTS WITH YOUR ARCHITECTURE
Review the full attack surface.
Use the catalog to ask better questions about your agents. It covers risks across identity, tools, memory, MCP, data and policy. A listed threat is an assessment topic, not a promise of automatic prevention.
Agent-to-agent threats6 topics
Risks in trust, authentication and decisions shared between agents.
- Interagent authentication exploits
- Agent trust exploitation
- Collaborative decision manipulation
- A2A collusion attacks
- A2A misinformation cascading
- Rogue agents
Memory poisoning4 topics
Corruption of the information an agent stores or retrieves as context.
- System memory poisoning
- Vector DB poisoning
- Object DB poisoning
- Database poisoning
Misaligned and deceptive behaviour3 topics
Behaviour that departs from intended goals or presents a misleading appearance of alignment.
- Threat alignment
- Alignment faking
- Excessive agency
Privilege compromise4 topics
Misuse of permissions, roles or delegated authority.
- Excessive permissions
- Confused deputy
- Overprovisioned agents
- OAuth scope violation
Remote code execution4 topics
Generated instructions or operations that introduce executable attacks.
- Malicious code generation
- SQL injection
- Malicious prompt generation
- API attacks
Identity spoofing and impersonation4 topics
An agent or user is represented as someone other than the authenticated actor.
- User impersonation
- Agent impersonation
- Behavioural mimicry
- Weak authentication
Agent social engineering2 topics
Actions designed to influence users or conceal activity.
- Manipulate users
- Covert actions
Resource overload3 topics
Agent behaviour that exhausts compute, quotas or execution capacity.
- Reflection loop trap
- API quota depletion
- Computational resource exhaustion
Sensitive and regulated data exposure4 topics
Disclosure of protected information through agent activity.
- PII data exposure
- PHI data exposure
- Intellectual property exposure
- Confidential data exposure
Tool misuse5 topics
Unsafe tools, compromised dependencies or harmful combinations of otherwise available operations.
- Risky commands
- Risky plugins
- Tool poisoning
- Supply chain attack
- Risky tool chaining
Intent breaking and goal manipulation5 topics
Inputs that attempt to redirect an agent from its authorized task.
- Direct prompt injection
- Indirect prompt injection
- Meta-learning vulnerability injection
- Prompt extraction
- XPIA
Overwhelming human review3 topics
Attacks on the effectiveness of human oversight and intervention.
- Trust mechanism subversion
- Cognitive overload
- Human intervention interface manipulation
MCP threats3 topics
Risks at Model Context Protocol integrations and connected servers.
- OAuth misconfiguration
- Prompt poisoning
- Server hijacking
Policy violations3 topics
Actions that cross defined access or information handling boundaries.
- Overshared data access
- ABAC violation
- Reclassification of sensitive documents