按 RiskScore v1.5 排序
注入分: 5.0
危害分: 3.57
Novelty: +4
accessibility: 1.000
∏d_Sink: 0.42
[PoisoningEntry] AttackerDMMessageBody(任意已配置渠道)
↓ allowFrom 未配置 + allowWhenEmpty=true
[Sink-0: SK-SYS-PROMPT] 消息注入 LLM 上下文(d=0.7)
↓ 20+ 渠道统一控制平面,message 工具支持任意渠道
[Sink-1: SK-NET] message 工具多渠道广播(d=0.6)
[Harm] SendToEvent → 受害者全部联系人/群组收到攻击者控制内容
SK-NET
AI-LATERAL-MOVE
AF-CHANNEL
TRG-RULE-TRIGGER
Perm-ACT-SEND
Sensitive-PII
注入分: 5.0
危害分: 4.032
Novelty: +2
前提: allowRequestSessionKey=true
∏d_Sink: 0.72
[PoisoningEntry] MaliciousWebhookRequest(T-AUTO=1.5)
↓ hooks.allowRequestSessionKey=true; 速率限制仅内存
[Sink-0: SK-INFO] Webhook 触达 Agent,请求 session key(d=0.8)
[Sink-1: SK-NET] session key 通过 Webhook 响应返回(d=0.9)
[Harm] LeakToEvent → 会话凭证外渗 → 会话劫持
SK-INFO
SK-NET
Auth-TYPE-NONE
TRG-EVENT-WEBHOOK
Sensitive-CREDENTIAL
注入分: 5.0
危害分: 1.508
Novelty: +4
∏d_Sink: 0.1764
[PoisoningEntry] AttackerDMMessageBody
↓
[Sink-0: SK-SYS-PROMPT] 消息注入(d=0.7)
[Sink-1: SK-TOOL-WRITE] 写 HEARTBEAT.md 恶意指令(d=0.6)
↓ 每个心跳周期自动重读,无需用户在线
[Sink-2: SK-INFO] read 凭证文件(d=0.6)
[Sink-3: SK-NET] message 外发到攻击者渠道(d=0.7)
[Harm] LeakToEvent → 凭证外渗 + 持续 C2(harmreversed=False)
SK-PERSIST
TRG-EVENT-HEARTBEAT
SK-INFO
SK-NET
AF-MEMORY
注入分: 5.0
危害分: 2.835
Novelty: +2
∏d_Sink: 0.35
[PoisoningEntry] AttackerDMMessageBody
[Sink-0: SK-SYS-PROMPT] 消息注入 LLM 上下文(d=0.7)
[Sink-1: SK-TOOL-WRITE] write 工具覆写 SOUL.md(d=0.5)
[Harm] TamperEvent → SOUL.md 内容永久注入所有后续会话系统提示词
INJ-TECH-WORKSPACE-OVERWRITE
SK-SYS-PROMPT
SK-PERSIST
AF-MEMORY
注入分: 5.0
危害分: 2.8
Novelty: +1
前提: security="full", ask="off"
[PoisoningEntry] AttackerDMOrWebhookMessage
[Sink-0] 消息注入 LLM 上下文(d=0.7)
[Sink-1: SK-EXEC] exec(security=full, ask=off → 无确认执行)(d=0.4)
[Harm] LeakToEvent/DeleteEvent → 任意 OS 命令,宿主系统控制
SK-EXEC
Perm-ACT-EXEC
Auth-TYPE-NONE
TOOL-ACT
注入分: 4.05
危害分: 2.52
Novelty: +1
accessibility: 0.9(C2×I1×P1)
[PoisoningEntry] MaliciousGmailEmailBody(allowUnsafeExternalContent=true)
[Sink-0] 邮件正文 → LLM 上下文(无内容净化)(d=0.7)
[Sink-1: SK-TOOL-COMM] 工具调用(读邮件+外发)(d=0.5)
[Harm] LeakToEvent → 用户邮件/联系人数据外渗
SK-NET
SK-TOOL-COMM
AF-CHANNEL
Sensitive-PII