Data ExfiltrationTier 2high
Data Exfiltration: System Info Harvest
Tricks to extract credentials, PII, or system information
System information harvesting probes for model details, tool configurations, and operational parameters. This reconnaissance data enables more targeted attacks.
Attack Details
- Attack ID
- APWN-DE-002
- HMA Check
- CRED-002
- Delivery Methods
- html-comment, invisible-span
- CWE
- CWE-200
- OASB Control
- 5.2
- Severity
- high
Remediation
If your AI agent is vulnerable to this attack, scan and fix with:
npx hackmyagent secure --check CRED-002