LLM ↓
ASI →
ASI01ASI01 — Agent Goal Hijack
ASI02ASI02 — Tool Misuse and Exploitation
ASI03ASI03 — Identity and Privilege Abuse
ASI04ASI04 — Agentic Supply Chain Vulnerabilities
ASI05ASI05 — Unexpected Code Execution (RCE)
ASI06ASI06 — Memory and Context Poisoning
ASI07ASI07 — Insecure Inter-Agent Communication
ASI08ASI08 — Cascading Failures
ASI09ASI09 — Human-Agent Trust Exploitation
ASI10ASI10 — Rogue Agents
LLM01LLM01 — Prompt Injection
3LLM01 × ASI01 — 3 findings- FinBot — An anonymous goal write persists into every later decision — stored custom_goals a
- FinBot — The fallback engine scores authority and urgency phrases out of the attacker-contr
- HelperBot — Attack detection classifies injections and then routes them into the matching expl
1LLM01 × ASI03 — 1 finding- HelperBot — Any network caller reaches HelperBot: the port binds all interfaces with wildcard
1LLM01 × ASI04 — 1 finding- yaah — Remote skill markdown and its third-party frontmatter are written into the host ag
3LLM01 × ASI05 — 3 findings- Deep Agents Code — Hostile repository content reaches the model as system-prompt text and can drive f
- Hermes Agent (with Hermes Desktop) — In non-interactive, non-gateway runs every non-hardline dangerous command and all
- CraftBot — Unlabeled external content reaches host shell execution in one hop, with the paren
3LLM01 × ASI06 — 3 findings- FinBot — An anonymous goal write persists into every later decision — stored custom_goals a
- aider — `--restore-chat-history` re-loads a transcript aider itself wrote, carrying earlie
- CraftBot — Session-loaded identity and memory files are agent-writable with no code guard, gi
LLM02LLM02 — Sensitive Information Disclosure
1LLM02 × ASI02 — 1 finding- CraftBot — No outbound destination control — the agent can POST to any public URL and email a
10LLM02 × ASI03 — 10 findings- HelperBot — Any network caller reaches HelperBot: the port binds all interfaces with wildcard
- OpenHands — The host-direct sandbox copies the app server's entire environment into the agent-
- OpenHands — The default secrets store writes git provider tokens and user custom secrets to di
- Deep Agents Code — The full process environment, including provider API keys, is copied into the runt
- yaah — The Notion MCP provider interpolates the operator's API token into a config value
- CraftBot — Live third-party OAuth client secrets and a Telegram API hash are shipped in sourc
- uAgents (Fetch.ai uAgent) — The agent inspector's REST endpoints are reachable by any remote or cross-origin c
- +3 more
1LLM02 × ASI07 — 1 finding- AutoGen Code Executor — The Jupyter kernel websocket URL is hardcoded to ws:// even when the connection is
LLM03LLM03 — Excessive Agency
4LLM03 × ASI02 — 4 findings- HelperBot — HelperBot's declared inventory contains write_file and search_web — a filesystem-w
- OpenHands — The Tavily MCP proxy is mounted as a top-level route rather than under the V1 rout
- yaah — MCP tool arguments reach the filesystem with no containment check, so reads and di
- uAgents (Fetch.ai uAgent) — Every handler receives an unrestricted wallet and ledger client, and the framework
6LLM03 × ASI03 — 6 findings- FinBot — Every /api/admin/* route — goals, thresholds, fraud toggle, invoice approval, vend
- OpenAI Customer Service Agent — Seat changes execute on any confirmation number the model supplies — update_seat p
- aider — Browser mode launches Streamlit with no bind address and no authentication, so the
- OpenHands — Eleven of the thirteen V1 API routers ship with no authentication dependency unles
- Hermes Agent (with Hermes Desktop) — Four gateway adapters opt out of the central default-deny and default their own DM
- CraftBot — The documented Docker deployment mounts the host Docker socket into the agent cont
1LLM03 × ASI04 — 1 finding- Deep Agents Code — MCP tools exempt themselves from the approval gate through a server-declared readO
11LLM03 × ASI05 — 11 findings- AutoGen Code Executor — The default executor factory silently downgrades from container isolation to host
- AutoGen Code Executor — The local executor's documented dangerous-command sanitizer does not exist anywher
- AutoGen Code Executor — DockerJupyterServer publishes a stateful arbitrary-code kernel gateway on every ho
- AutoGen Code Executor — The executor contract has no approval interposition point; every backend runs a su
- AutoGen Code Executor — JupyterCodeExecutor runs LLM-generated code in a host kernel with no isolation, no
- AutoGen Code Executor — Function setup installs packages into the host interpreter and compiles function s
- aider — Auto-lint runs a shell command after every edit with no pre-execution confirmation
- +4 more
1LLM03 × ASI09 — 1 finding- Hermes Agent (with Hermes Desktop) — With approvals.mode set to smart, an auxiliary LLM resolves the destructive-comman
3LLM03 × ASI10 — 3 findings- Deep Agents Code — Headless mode approves every non-shell side-effecting tool unconditionally — file
- yaah — Every generated /yaah:* command, including the autonomous phase runner, is model-i
- CraftBot — The documented approval architecture is enforced nowhere in code — permission_tier
LLM04LLM04 — Supply Chain
5LLM04 × ASI04 — 5 findings- HelperBot — Three of six direct dependencies are caret-ranged and the image builds with npm in
- yaah — Default generation wires outbound MCP servers that install unpinned npm packages a
- Hermes Agent (with Hermes Desktop) — The desktop first-run and repair install pipes a remote shell script straight into
- CraftBot — Both default-enabled MCP servers resolve unpinned upstream packages on every start
- uAgents (Fetch.ai uAgent) — Both published distributions declare unbounded dependency floors, and no dependenc
1LLM04 × ASI06 — 1 finding- Hermes Agent (with Hermes Desktop) — Skills the agent writes for itself bypass Skills Guard entirely because the gate t
LLM05LLM05 — Data and Model Poisoning
LLM06LLM06 — Unbounded Consumption
1LLM06 × ASI07 — 1 finding- uAgents (Fetch.ai uAgent) — The default inbound path applies no counterparty allowlist and no rate limit, so a
LLM07LLM07 — Misinformation
LLM08LLM08 — Hidden Context Exposure
LLM09LLM09 — Vector and Embedding Weaknesses
LLM10LLM10 — Improper Output Handling
1LLM10 × ASI02 — 1 finding- aider — Model-supplied file paths are resolved with no repo-root containment, and the oper
4LLM10 × ASI05 — 4 findings- Deep Agents Code — Hostile repository content reaches the model as system-prompt text and can drive f
- yaah — The fail-closed command guard is seven regexes over a shell, so trivial rewrites o
- yaah — The yaah_lint MCP tool spawns external binaries on a model-supplied path without c
- CraftBot — Unlabeled external content reaches host shell execution in one hop, with the paren