Mappings
Every technique against the frameworks it touches. Generated from the catalog - pick an axis to pivot. Codes with no technique yet are gaps to fill.
LLM01 Prompt Injection
Adversarial Suffix (GCG)Agent Communication PoisoningCrescendo (Multi-Turn Escalation)Direct Prompt InjectionGuardrail / Refusal BypassIndirect Prompt InjectionMany-Shot JailbreakSkeleton Key (Policy-Update Jailbreak)Deceptive DelightEcho Chamber (Context Poisoning)Encoding & Obfuscation BypassPayload Splitting / Token SmugglingRefusal SuppressionRoleplay / Persona Jailbreak (DAN-style)
LLM02 Sensitive Information Disclosure
LLM03 Supply Chain
LLM04 Data & Model Poisoning
LLM05 Improper Output Handling
LLM06 Excessive Agency
Confused Deputy (Cross-Tool Authority Abuse)MCP Direct Access (Bypass the Chatbot)Multi-Agent Privilege Escalation (Shared-State Poisoning)Race Condition / TOCTOU (Double-Spend)Rogue / Misaligned Sub-AgentSSRF via Fetch/URL ToolTool-Invocation Privilege EscalationHuman-in-the-Loop Fatigue (Approval Flooding)Repudiation & Untraceability
LLM07 System Prompt Leakage
LLM08 Vector & Embedding Weaknesses
LLM09 Misinformation
LLM10 Unbounded Consumption
ASI01 Agent Goal Hijack
Adversarial Suffix (GCG)Crescendo (Multi-Turn Escalation)Direct Prompt InjectionIndirect Prompt InjectionMany-Shot JailbreakSkeleton Key (Policy-Update Jailbreak)Deceptive DelightEcho Chamber (Context Poisoning)Encoding & Obfuscation BypassPayload Splitting / Token SmugglingRefusal SuppressionRoleplay / Persona Jailbreak (DAN-style)System Prompt Leakage
ASI02 Tool Misuse
ASI03 Identity & Privilege Abuse
ASI04 Supply Chain Vulnerabilities
ASI05 Unexpected Code Execution
ASI06 Memory & Context Poisoning
ASI07 Insecure Inter-Agent Communication
ASI08 Cascading Failures
ASI09 Human-Agent Trust Exploitation
ASI10 Rogue Agents
T1 Memory Poisoning
T2 Tool Misuse
T3 Privilege Compromise
T4 Resource Overload
T5 Cascading Hallucination Attacks
T6 Intent Breaking & Goal Manipulation
Adversarial Suffix (GCG)Crescendo (Multi-Turn Escalation)Direct Prompt InjectionIndirect Prompt InjectionMany-Shot JailbreakSkeleton Key (Policy-Update Jailbreak)Deceptive DelightEcho Chamber (Context Poisoning)Encoding & Obfuscation BypassPayload Splitting / Token SmugglingRefusal SuppressionRoleplay / Persona Jailbreak (DAN-style)System Prompt Leakage
T7 Misaligned & Deceptive Behaviors
T8 Repudiation & Untraceability
T9 Identity Spoofing & Impersonation
T10 Overwhelming Human-in-the-Loop
T11 Unexpected RCE & Code Attacks
T12 Agent Communication Poisoning
T13 Rogue Agents in Multi-Agent Systems
T14 Human Attacks on Multi-Agent Systems
T15 Human Manipulation
AML.T0024 Exfiltration via AI Inference API
AML.T0043 Craft Adversarial Data
AML.T0048 External Harms
AML.T0051 LLM Prompt Injection
AML.T0051.000 LLM Prompt Injection - Direct
AML.T0051.001 LLM Prompt Injection - Indirect
AML.T0053 Compromise LLM Plugins
AML.T0054 LLM Jailbreak
AML.T0056 LLM Meta Prompt Extraction
AML.T0057 LLM Data Leakage
CWE-94 Improper Control of Generation of Code (Code Injection)
CWE-209 Generation of Error Message Containing Sensitive Information
CWE-214 Invocation of Process Using Visible Sensitive Information
CWE-367 TOCTOU Race Condition
CWE-400 Uncontrolled Resource Consumption
CWE-436 Interpretation Conflict (Parser Differential)
CWE-441 Unintended Proxy or Intermediary (Confused Deputy)
CWE-502 Deserialization of Untrusted Data
CWE-522 Insufficiently Protected Credentials
CWE-918 Server-Side Request Forgery (SSRF)
CWE-1336 Improper Neutralization of Special Elements Used in a Template Engine