T-3006ValidatedActive20 evidence records

Context Window Credential Leak

Exploit context window contents to leak credentials that were previously processed by the agent

Tactic

Credential Harvest · Stage 3

Extract API keys, tokens, and credentials from agent context and connected services

Attack class

RETROACTIVE-PRIV

Exploiting previously granted access or cached credentials to gain unauthorized capabilities

Evidence grade
Validated

Reproduced in a controlled lab environment (DVAA) with documented steps.

DVAA validation

LegacyBot credential leak

Reproductions in Damn Vulnerable AI Agent, the OpenA2A intentionally-broken agent for kill-chain validation.

Honeypot

AgentPwn coverage

Live

An AgentPwn trap page produces a payload tagged with this technique class. Following the AgentPwn taxonomy of trap pages shows what an agent encounters.

Context-window tiers leak credentials retained in the active window.

Provenance

Evidence by source

HackMyAgent
20 records
Trail

Evidence timeline

HackMyAgent

HMA check CRED-001 failed on cred-test

Jun 2, 2026
HackMyAgent

HMA check CRED-001 failed on cred-test

May 28, 2026
HackMyAgent

HMA check AGENT-CRED-001 failed on ai-trust

May 28, 2026
HackMyAgent

HMA check CRED-001 failed on cred-test

May 27, 2026
HackMyAgent

HMA check CRED-001 failed on cred-test

May 25, 2026
HackMyAgent

HMA check CRED-001 failed on cred-test

May 24, 2026
HackMyAgent

HMA check CRED-001 failed on cred-test

May 21, 2026
HackMyAgent

HMA check CRED-001 failed on cred-test

May 12, 2026
HackMyAgent

HMA check CRED-001 failed on cred-test

May 11, 2026
HackMyAgent

HMA check CRED-001 failed on cred-test

Apr 30, 2026
HackMyAgent

HMA check CRED-001 failed on soc-demo

Apr 30, 2026
HackMyAgent

HMA check CRED-001 failed on opena2a-cli

Apr 29, 2026
HackMyAgent

HMA check CRED-001 failed on cred-test

Apr 29, 2026
HackMyAgent

HMA check CRED-001 failed on cred-test

Apr 28, 2026
HackMyAgent

HMA check CRED-001 failed on cred-test

Apr 27, 2026
HackMyAgent

HMA check CRED-001 failed on cred-test

Apr 22, 2026
HackMyAgent

HMA check AGENT-CRED-001 failed on triggerdotdev/trigger.dev

Apr 9, 2026
HackMyAgent

HMA check AGENT-CRED-001 failed on @khanglvm/jira-mcp

Apr 9, 2026
HackMyAgent

HMA check AGENT-CRED-001 failed on nwiizo/tfmcp

Apr 9, 2026
HackMyAgent

HMA check AGENT-CRED-001 failed on saidsurucu/borsa-mcp

Apr 9, 2026
Detect

Detection · HackMyAgent

Live2 live · 0 queued
CRED-001AGENT-CRED-001
npx hackmyagent secure --ciLive = implemented in hackmyagent; queued = declared
Defend

Defense · OASB controls

Live5 live · 0 queued
Live = documented at oasb.ai; queued = declared
Reference

How to cite

AI Agent Threat Matrix T-3006 (Context Window Credential Leak). OpenA2A, 2026. https://threats.opena2a.org/techniques/T-3006