Configuration Modification
Modify agent or gateway configuration files to maintain persistent access
Persistence · Stage 6
Establish persistent access surviving restarts and session changes
GATEWAY-EXPLOIT
Modifying gateway or proxy configurations to intercept, redirect, or manipulate agent traffic
Confirmed in real-world production systems or internet-wide exposure assessments.
config modification
Reproductions in Damn Vulnerable AI Agent, the OpenA2A intentionally-broken agent for kill-chain validation.
AgentPwn coverage
Not observable via content-side honeypot interaction. HackMyAgent or DVAA cover this where applicable.
Modifying the agent's own config on its host is not observable via web content.
Evidence by source
Evidence timeline
HMA check GATEWAY-002 failed on fake-vulnerable-agent
HMA check GATEWAY-002 failed on fake-vulnerable-agent
HMA check GATEWAY-002 failed on fake-vulnerable-agent
HMA check GATEWAY-002 failed on fake-vulnerable-agent
Detection · HackMyAgent
npx hackmyagent secure --ciLive = implemented in hackmyagent; queued = declaredDefense · OASB controls
How to cite
AI Agent Threat Matrix T-6003 (Configuration Modification). OpenA2A, 2026. https://threats.opena2a.org/techniques/T-6003