Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
22,862 changes: 9,552 additions & 13,310 deletions data/backlinks.json

Large diffs are not rendered by default.

132 changes: 68 additions & 64 deletions data/entries/ASI01.json
Original file line number Diff line number Diff line change
Expand Up @@ -157,8 +157,8 @@
},
{
"framework": "EU AI Act",
"control_id": "Goal hijack scenarios identified and mitigated in risk management system",
"control_name": "Art. 9 — Risk management",
"control_id": "Art. 9",
"control_name": "Risk management",
"tier": "Foundational",
"scope": "Both",
"notes": "Agent goal hijack included in Art. 9 risk assessment for every agentic deployment",
Expand All @@ -167,8 +167,8 @@
},
{
"framework": "EU AI Act",
"control_id": "Meaningful human oversight over high-risk AI system outputs",
"control_name": "Art. 14 — Human oversight",
"control_id": "Art. 14",
"control_name": "Human oversight",
"tier": "Foundational",
"scope": "Both",
"notes": "Agents whose goals can be hijacked and execute autonomously are an Art. 14 failure — human confirmation required before goal-changing actions",
Expand All @@ -177,8 +177,8 @@
},
{
"framework": "EU AI Act",
"control_id": "Technical resilience against adversarial input manipulation",
"control_name": "Art. 15 — Accuracy, robustness, cybersecurity",
"control_id": "Art. 15",
"control_name": "Accuracy, robustness, cybersecurity",
"tier": "Foundational",
"scope": "Both",
"notes": "Input filtering, goal-state verification, and injection detection are Art. 15 technical requirements",
Expand Down Expand Up @@ -257,7 +257,7 @@
},
{
"framework": "ISO/IEC 42001:2023",
"control_id": "Cl.6.1",
"control_id": "6.1",
"control_name": "Risk assessment",
"tier": "Foundational",
"scope": "Both",
Expand All @@ -267,40 +267,44 @@
},
{
"framework": "CIS Controls v8.1",
"control_id": "16.1 Establish secure application development standards",
"control_name": "CIS 16 — Application Software Security",
"control_id": "16.1",
"control_name": "Establish secure application development standards",
"tier": "Foundational",
"scope": "Both",
"parent": "CIS-16",
"notes": "Secure development standards covering agentic integrations — input validation, goal-state verification",
"confidence": "unreviewed",
"reviewed_by": []
},
{
"framework": "CIS Controls v8.1",
"control_id": "18.1 Establish penetration testing programme",
"control_name": "CIS 18 — Penetration Testing",
"control_id": "18.1",
"control_name": "Establish penetration testing programme",
"tier": "Foundational",
"scope": "Both",
"parent": "CIS-18",
"notes": "Adversarial testing covering goal hijack — direct, indirect, multi-turn injection scenarios",
"confidence": "unreviewed",
"reviewed_by": []
},
{
"framework": "CIS Controls v8.1",
"control_id": "8.2 Collect audit logs",
"control_name": "CIS 8 — Audit Log Management",
"control_id": "8.2",
"control_name": "Collect audit logs",
"tier": "Foundational",
"scope": "Both",
"parent": "CIS-8",
"notes": "All agent inputs logged — injection attempts detectable through log analysis",
"confidence": "unreviewed",
"reviewed_by": []
},
{
"framework": "CIS Controls v8.1",
"control_id": "13.8 Deploy a network intrusion detection solution",
"control_name": "CIS 13 — Network Monitoring and Defence",
"control_id": "13.8",
"control_name": "Deploy a network intrusion detection solution",
"tier": "Foundational",
"scope": "Both",
"parent": "CIS-13",
"notes": "Network-layer monitoring for injection indicators in agent traffic",
"confidence": "unreviewed",
"reviewed_by": []
Expand Down Expand Up @@ -407,8 +411,8 @@
},
{
"framework": "NIST SP 800-82 Rev 3",
"control_id": "Vulnerabilities common to IT/OT",
"control_name": "§5.3",
"control_id": "§5.3",
"control_name": "Vulnerabilities common to IT/OT",
"tier": "Foundational",
"scope": "Both",
"notes": "Injection via historian and SCADA data feeds",
Expand All @@ -417,8 +421,8 @@
},
{
"framework": "NIST SP 800-82 Rev 3",
"control_id": "Risk assessment",
"control_name": "§6.2",
"control_id": "§6.2",
"control_name": "Risk assessment",
"tier": "Foundational",
"scope": "Both",
"notes": "Assess injection risk at every agent data ingestion point",
Expand All @@ -427,8 +431,8 @@
},
{
"framework": "NIST SP 800-82 Rev 3",
"control_id": "Security controls for ICS",
"control_name": "§7.2",
"control_id": "§7.2",
"control_name": "Security controls for ICS",
"tier": "Foundational",
"scope": "Both",
"notes": "Input validation mandatory at OT data boundary",
Expand Down Expand Up @@ -477,8 +481,8 @@
},
{
"framework": "SOC 2",
"control_id": "Goal hijack risk identified in risk assessment — prompt injection, indirect injection, multi-turn manipulation documented",
"control_name": "CC3.2",
"control_id": "CC3.2",
"control_name": "COSO principle 7 — Risk identification and analysis",
"tier": "Foundational",
"scope": "Both",
"notes": "Risk register with goal hijack entries, treatment status",
Expand All @@ -487,8 +491,8 @@
},
{
"framework": "SOC 2",
"control_id": "Runtime monitoring for goal-deviation indicators — AI-specific anomaly detection covering instruction-override patterns",
"control_name": "CC7.2",
"control_id": "CC7.2",
"control_name": "Event monitoring",
"tier": "Foundational",
"scope": "Both",
"notes": "Monitoring configuration, alert logs, incident records",
Expand All @@ -497,8 +501,8 @@
},
{
"framework": "SOC 2",
"control_id": "Control activities define acceptable agent actions — agent cannot deviate from authorised goal scope",
"control_name": "CC5.2",
"control_id": "CC5.2",
"control_name": "COSO principle 11 — Technology controls",
"tier": "Foundational",
"scope": "Both",
"notes": "Agent permission policy, goal-state verification design documentation",
Expand All @@ -507,8 +511,8 @@
},
{
"framework": "SOC 2",
"control_id": "Agent processing is authorised — actions taken by agent correspond to user's authorised intent, not attacker's injected instruction",
"control_name": "PI1.1",
"control_id": "PI1.1",
"control_name": "Processing integrity — input completeness and accuracy",
"tier": "Foundational",
"scope": "Both",
"notes": "Action audit log, authorisation records per agent session",
Expand All @@ -517,8 +521,8 @@
},
{
"framework": "PCI DSS v4.0",
"control_id": "Bespoke agent code reviewed for injection resistance — all agent integration code includes prompt injection as a vulnerability category",
"control_name": "Req 6.2",
"control_id": "Req 6.2",
"control_name": "Bespoke software security",
"tier": "Foundational",
"scope": "Both",
"notes": "Secure code review records, findings, remediation",
Expand All @@ -527,7 +531,7 @@
},
{
"framework": "PCI DSS v4.0",
"control_id": "Penetration testing covers goal hijack — agentic AI systems tested for prompt injection before production and annually",
"control_id": "Req 11.3",
"control_name": "Req 11.3",
"tier": "Foundational",
"scope": "Both",
Expand All @@ -537,7 +541,7 @@
},
{
"framework": "PCI DSS v4.0",
"control_id": "Agent actions logged — all goal-relevant agent actions logged with user identity, session ID, and action detail",
"control_id": "Req 10.2",
"control_name": "Req 10.2",
"tier": "Foundational",
"scope": "Both",
Expand All @@ -547,7 +551,7 @@
},
{
"framework": "PCI DSS v4.0",
"control_id": "Targeted risk analysis documents goal hijack — likelihood, impact on CHD, treatment controls specified",
"control_id": "Req 12.3",
"control_name": "Req 12.3",
"tier": "Foundational",
"scope": "Both",
Expand Down Expand Up @@ -657,8 +661,8 @@
},
{
"framework": "CWE/CVE",
"control_id": "Improper Input Validation",
"control_name": "CWE-20",
"control_id": "CWE-20",
"control_name": "Improper Input Validation",
"tier": "Foundational",
"scope": "Both",
"notes": "Root cause — agent inputs not validated before entering model context; indirect injection content not treated as untrusted",
Expand All @@ -667,8 +671,8 @@
},
{
"framework": "CWE/CVE",
"control_id": "Improper Neutralisation of Special Elements in Output Used by a Downstream Component",
"control_name": "CWE-74",
"control_id": "CWE-74",
"control_name": "Improper Neutralisation of Special Elements in Output Used by a Downstream Component",
"tier": "Foundational",
"scope": "Both",
"notes": "Instruction elements in processed content not neutralised before agent reasoning",
Expand All @@ -677,8 +681,8 @@
},
{
"framework": "CWE/CVE",
"control_id": "Protection Mechanism Failure",
"control_name": "CWE-693",
"control_id": "CWE-693",
"control_name": "Protection Mechanism Failure",
"tier": "Foundational",
"scope": "Both",
"notes": "Safety and goal-verification controls bypassed through injection",
Expand All @@ -687,8 +691,8 @@
},
{
"framework": "CWE/CVE",
"control_id": "Unintended Proxy or Intermediary",
"control_name": "CWE-441",
"control_id": "CWE-441",
"control_name": "Unintended Proxy or Intermediary",
"tier": "Foundational",
"scope": "Both",
"notes": "Agent acts as a proxy executing attacker instructions against backend systems",
Expand All @@ -697,8 +701,8 @@
},
{
"framework": "CWE/CVE",
"control_id": "Externally Controlled Reference to a Resource in Another Sphere",
"control_name": "CWE-610",
"control_id": "CWE-610",
"control_name": "Externally Controlled Reference to a Resource in Another Sphere",
"tier": "Foundational",
"scope": "Both",
"notes": "Agent retrieves and acts on externally controlled content (RAG, email, tool returns) without adequate validation",
Expand All @@ -707,8 +711,8 @@
},
{
"framework": "OWASP AI Testing Guide",
"control_id": "Prompt injection via all agent input channels",
"control_name": "IHT — Input Handling",
"control_id": "IHT",
"control_name": "Input Handling",
"tier": "Foundational",
"scope": "Both",
"notes": "Inject instruction-overriding content through user prompt, RAG-retrieved documents, tool return values, email content, uploaded files, and any other data source the agent processes",
Expand All @@ -717,8 +721,8 @@
},
{
"framework": "OWASP AI Testing Guide",
"control_id": "Goal consistency under adversarial input",
"control_name": "MBT — Model Behaviour",
"control_id": "MBT",
"control_name": "Model Behaviour",
"tier": "Foundational",
"scope": "Both",
"notes": "Verify the agent's stated goal at session start matches its actions at session end — test divergence after indirect injection",
Expand All @@ -727,8 +731,8 @@
},
{
"framework": "OWASP AI Testing Guide",
"control_id": "Goal state verification effectiveness",
"control_name": "AST — Agent-Specific",
"control_id": "AST",
"control_name": "Agent-Specific",
"tier": "Foundational",
"scope": "Both",
"notes": "Attempt to redirect agent goal through indirect injection paths specific to your deployment — historian data, vendor communications, web results",
Expand Down Expand Up @@ -800,8 +804,8 @@
},
{
"framework": "OWASP NHI Top 10",
"control_id": "Hijacked agent with excess privilege causes larger blast radius",
"control_name": "NHI-5 Over-Privileged NHI",
"control_id": "NHI-5",
"control_name": "Over-Privileged NHI",
"tier": "Foundational",
"scope": "Both",
"notes": "Scope all agent credentials to minimum required — least privilege enforced",
Expand All @@ -810,8 +814,8 @@
},
{
"framework": "OWASP NHI Top 10",
"control_id": "Long-lived tokens allow hijack to persist beyond session",
"control_name": "NHI-7 Long-Lived Credentials",
"control_id": "NHI-7",
"control_name": "Long-Lived Credentials",
"tier": "Foundational",
"scope": "Both",
"notes": "Short-lived credentials — tokens expire at task completion, no long-lived agent tokens",
Expand All @@ -820,8 +824,8 @@
},
{
"framework": "OWASP NHI Top 10",
"control_id": "Shared credentials allow hijacked agent to impersonate other agents",
"control_name": "NHI-9 NHI Reuse",
"control_id": "NHI-9",
"control_name": "NHI Reuse",
"tier": "Foundational",
"scope": "Both",
"notes": "Unique identity per agent — no shared service accounts across agent deployments",
Expand All @@ -830,8 +834,8 @@
},
{
"framework": "NIST SP 800-218A",
"control_id": "Threat model the agent pipeline for adversarial goal manipulation vectors including direct injection, indirect injection via tool outputs, and context poisoning",
"control_name": "PW.2.1-PS – Design software to meet security requirements",
"control_id": "PW.2.1-PS",
"control_name": "Design software to meet security requirements",
"tier": "Foundational",
"scope": "Both",
"notes": "Ensures goal integrity is a design-phase requirement for all agentic systems",
Expand All @@ -840,8 +844,8 @@
},
{
"framework": "NIST SP 800-218A",
"control_id": "Review agent behaviour for goal deviation — verify that the agent maintains intended objectives under adversarial input conditions",
"control_name": "PW.7.2-PS – Review the software for security vulnerabilities",
"control_id": "PW.7.2-PS",
"control_name": "Review the software for security vulnerabilities",
"tier": "Foundational",
"scope": "Both",
"notes": "Catches goal manipulation vulnerabilities before production deployment",
Expand All @@ -850,8 +854,8 @@
},
{
"framework": "NIST SP 800-218A",
"control_id": "Conduct adversarial red-team testing against goal hijacking vectors including injection through every data source, tool output, and context channel",
"control_name": "PW.8.2-PS – Test for security vulnerabilities",
"control_id": "PW.8.2-PS",
"control_name": "Test for security vulnerabilities",
"tier": "Foundational",
"scope": "Both",
"notes": "Validates goal integrity controls under realistic attack conditions",
Expand All @@ -860,8 +864,8 @@
},
{
"framework": "NIST SP 800-218A",
"control_id": "Establish procedures to identify goal hijacking incidents in production including goal deviation monitoring, triage, and confirmation workflows",
"control_name": "RV.1.1-PS – Identify and confirm vulnerabilities",
"control_id": "RV.1.1-PS",
"control_name": "Identify and confirm vulnerabilities",
"tier": "Foundational",
"scope": "Both",
"notes": "Enables rapid detection and response to goal manipulation in live systems",
Expand Down
Loading
Loading