T-3003ValidatedActive15 evidence records

Tool Response Credential Capture

Capture credentials returned in tool or API responses that pass through the agent's context

Tactic

Credential Harvest · Stage 3

Extract API keys, tokens, and credentials from agent context and connected services

Attack class

RETROACTIVE-PRIV

Exploiting previously granted access or cached credentials to gain unauthorized capabilities

Evidence grade
Validated

Reproduced in a controlled lab environment (DVAA) with documented steps.

DVAA validation

ToolBot credential responses

Reproductions in Damn Vulnerable AI Agent, the OpenA2A intentionally-broken agent for kill-chain validation.

Honeypot

AgentPwn coverage

Queued

In scope for honeypot observation; trap page or telemetry hook not yet built.

Capturing creds from a fake tool response needs an MCP fixture that returns secrets; not yet wired.

Provenance

Evidence by source

HackMyAgent
15 records
Trail

Evidence timeline

HackMyAgent

HMA check CRED-001 failed on cred-test

Jun 2, 2026
HackMyAgent

HMA check CRED-001 failed on cred-test

May 28, 2026
HackMyAgent

HMA check CRED-001 failed on cred-test

May 27, 2026
HackMyAgent

HMA check CRED-001 failed on cred-test

May 25, 2026
HackMyAgent

HMA check CRED-001 failed on cred-test

May 24, 2026
HackMyAgent

HMA check CRED-001 failed on cred-test

May 21, 2026
HackMyAgent

HMA check CRED-001 failed on cred-test

May 12, 2026
HackMyAgent

HMA check CRED-001 failed on cred-test

May 11, 2026
HackMyAgent

HMA check CRED-001 failed on cred-test

Apr 30, 2026
HackMyAgent

HMA check CRED-001 failed on soc-demo

Apr 30, 2026
HackMyAgent

HMA check CRED-001 failed on opena2a-cli

Apr 29, 2026
HackMyAgent

HMA check CRED-001 failed on cred-test

Apr 29, 2026
HackMyAgent

HMA check CRED-001 failed on cred-test

Apr 28, 2026
HackMyAgent

HMA check CRED-001 failed on cred-test

Apr 27, 2026
HackMyAgent

HMA check CRED-001 failed on cred-test

Apr 22, 2026
Detect

Detection · HackMyAgent

Live1 live · 0 queued
CRED-001
npx hackmyagent secure --ciLive = implemented in hackmyagent; queued = declared
Defend

Defense · OASB controls

Live5 live · 0 queued
Live = documented at oasb.ai; queued = declared
Reference

How to cite

AI Agent Threat Matrix T-3003 (Tool Response Credential Capture). OpenA2A, 2026. https://threats.opena2a.org/techniques/T-3003