ai.prompt_injection.direct |
Direct prompt injection Structured injection verdicts and deterministic instruction-override signals in received or scanned prompts. |
prompt injection |
high |
Concept |
ai.prompt_injection.indirect |
Indirect prompt injection Untrusted retrieved instructions correlated with a later sensitive tool proposal in the same trace. |
prompt injection |
high |
Concept |
ai.tool.unauthorized |
Unauthorized tool use Tools outside the agent's grants, policy-denied proposals, and execution after a denial. |
excessive agency |
high |
Concept |
ai.data.sensitive_exposure |
Sensitive data exposure Scanner and policy signals on outputs and transfers, evaluated without storing the raw values. |
data access abuse |
high |
Concept |
ai.rag.poisoning |
RAG poisoning or contamination A suspicious retrieved document, distinguished from confirmed influence over a risky action. |
supply chain |
medium |
Concept |
ai.intent_action.divergence |
Intent-action divergence Declared task category compared with the explicit tool category and side effects. |
causal hijack |
high |
Concept |
ai.action.concealment_risk |
Concealed action risk A benign final status that omits risky or blocked effects recorded earlier in the trace. |
causal hijack |
medium |
Concept |
ai.control.repeated_failure |
Repeated security control failure Repeated policy denials or guardrail failures aggregated over a bounded window (3 in 60 minutes by default). |
excessive agency |
high |
Concept |
ai.tool.risk_misdeclared |
Tool risk declared below its inferred class A tool call declared a category or governance class below what its name implies; declarations can escalate, never downgrade. |
excessive agency |
medium |
Concept |
ai.mcp.tool_poisoning |
MCP tool poisoning Model-directed instructions inside an MCP tool description, or a description that changed between sightings in one trace. |
supply chain |
high |
Concept |
ai.mcp.approval_bypass |
Privileged tool call bypassed its gate A destructive- or secrets-class tool executed with no broker decision in a trace where other calls were gated. |
excessive agency |
high |
Concept |
ai.mcp.tool_shadowing |
MCP tool name collision Two MCP servers exposed or served the same tool name inside one execution trace. |
supply chain |
medium |
Concept |