Taxonomy · Attack Classes

40 attack classes, grouped by vulnerability pattern

Each class collects related techniques that share a root cause or exploitation pattern. Classes are organized into six categories spanning agent governance, the software supply chain, runtime infrastructure, identity, sandboxing, and NemoClaw-specific exposure.

Governance

Governance

11 attack classes in this category.

ASSEMBLY-INJECT1 technique

Context Assembly Pipeline Injection

Attacks targeting the system prompt assembly process where components combine into exploitable injections

Detection · 10 checks
LIFECYCLE-001LIFECYCLE-002LIFECYCLE-003LIFECYCLE-004LIFECYCLE-005LIFECYCLE-006+4 more
PHANTOM-SOUL1 technique

Phantom Soul

Agent deployed with zero behavioral constraints — no SOUL.md, no system prompt, no governance

Detection · 2 checks
SOUL-HB-001SOUL-HB-002
SOUL-BOUNDARY1 technique

Soul Boundary Bypass

Exploiting ambiguous or incomplete constraint definitions to find unguarded actions

Detection · 2 checks
SOUL-CB-001SOUL-CB-002
SOUL-DELEGATE1 technique

SOUL Delegation Abuse

Exploiting delegation and capability transfer mechanisms to exceed authorized scope

Detection · 2 checks
SOUL-DH-001SOUL-DH-002
SOUL-FORK1 technique

Soul Forking

Different behavior under evaluation vs production — agent passes safety tests but behaves differently in deployment

Detection · 5 checks
CONFIG-006SOUL-AS-001SOUL-AS-002SOUL-HT-001SOUL-HT-002
SOUL-IMPERSONATE1 technique

Soul Impersonation

False capability claims exceeding actual authorization level

Detection · 1 check
SOUL-TH-005
Supply Chain

Supply Chain

11 attack classes in this category.

FAKETOOL-INJECT1 technique

Tool Impersonation and Injection

MCP tool impersonation, squatting, and schema poisoning attacks

Detection · 10 checks
FAKETOOL-001FAKETOOL-002FAKETOOL-003FAKETOOL-004FAKETOOL-005FAKETOOL-006+4 more
PERSIST-STATE1 technique

Persistent State Manipulation

Cross-session persistence via memory poisoning, state tampering, and cached context injection

Detection · 10 checks
PERSIST-001PERSIST-002PERSIST-003PERSIST-004PERSIST-005PERSIST-006+4 more
SKILL-MEM-AMP1 technique

Skill Memory Amplification

Skill plants payload in agent memory that survives skill uninstall — cross-session persistence

Detection · 1 check
SKILL-MEM-001
SUPPLY-CHAIN-INSTALL1 technique

Supply Chain Install Attack

Unsigned installation scripts executed without integrity verification — curl|sh without checksum

Detection · 1 check
INSTALL-001
Infrastructure

Infrastructure

10 attack classes in this category.

CODE-INJECTION2 techniques

Code Injection

Injecting and executing arbitrary code through SQL injection, command injection, or code generation

Detection · 7 checks
CODEINJ-001DOCKERINJ-001INJ-001INJ-002INJ-003INJ-004+1 more
GATEWAY-EXPLOIT1 technique

Gateway Configuration Exploitation

Modifying gateway or proxy configurations to intercept, redirect, or manipulate agent traffic

Detection · 11 checks
API-001API-002API-004GATEWAY-001GATEWAY-002GATEWAY-003+5 more
INTEGRITY-BYPASS1 technique

Integrity Check Bypass

Digest or hash verification bypass on empty or missing values — tampered artifacts pass silently

Detection · 13 checks
AUDIT-001AUDIT-002AUDIT-003AUDIT-004INTEGRITY-001LOG-001+7 more
PARSER-DIFFERENTIAL1 technique

Parser Differential Exploitation

Exploits differences between parser implementations to bypass security controls

Detection · 10 checks
PARSE-001PARSE-002PARSE-003PARSE-004PARSE-005PARSE-006+4 more
RETROACTIVE-PRIV9 techniques

Retroactive Privilege Exploitation

Exploiting previously granted access or cached credentials to gain unauthorized capabilities

Detection · 49 checks
AGENT-CRED-001API-003API-KEY-EXPOSEDAUTH-001AUTH-002AUTH-003+43 more
TOCTOU-RACE1 technique

TOCTOU Race Condition

Time-of-check-time-of-use race between verification and execution — swap window for attackers

Detection · 1 check
TOCTOU-001
NemoClaw-Specific

NemoClaw-Specific

5 attack classes in this category.

NEMO-OPENCLAW-INHERIT1 technique

NemoClaw OpenClaw Inheritance

Inherited OpenClaw flaws that survive NemoClaw sandboxing — heartbeat persistence, pre-allowed APIs

Detection · 4 checks
HMA-NMC-040HMA-NMC-041HMA-NMC-042NEMO-010
NEMO-SANDBOX-ESCAPE1 technique

Sandbox Escape

Breaking out of agent sandbox restrictions to access the underlying file system or OS

Detection · 21 checks
CONFIG-003CONFIG-008HMA-NMC-030HMA-NMC-031HMA-NMC-032HMA-NMC-033+15 more
NEMO-SUPPLY-CHAIN1 technique

Supply Chain Attack

Compromising upstream dependencies or infrastructure to affect downstream agent deployments

Detection · 8 checks
HMA-NMC-020HMA-NMC-021HMA-NMC-022HMA-NMC-023HMA-NMC-024NEMO-001+2 more
Identity

Identity

2 attack classes in this category.

BEHAVIORAL-IMPERSONATE1 technique

Behavioral Impersonation

Using stolen credentials detected via behavioral baseline mismatch — agent DNA forgery

Detection · 3 checks
DNA-001DNA-002DNA-003
Sandbox

Sandbox

1 attack class in this category.

SANDBOX-ESCAPE1 technique

Sandbox Escape

General sandbox escape via privileged containers, LSM degradation, or process environment leakage

Detection · 7 checks
SANDBOX-001SANDBOX-002SANDBOX-003SANDBOX-004SANDBOX-005SEM-PERM-003+1 more

Looking for how these classes chain into full attacks? See the attack paths or the kill-chain grid.