Configuration Modification
Modify agent or gateway configuration files to maintain persistent access
Tactic
Persistence (Stage 6)
Establish persistent access surviving restarts and session changes
Attack Class
GATEWAY-EXPLOIT
Modifying gateway or proxy configurations to intercept, redirect, or manipulate agent traffic
Evidence
Confirmed in real-world production systems or internet-wide exposure assessments.
DVAA Validation
Reproductions in Damn Vulnerable AI Agent, the OpenA2A intentionally-broken agent for kill-chain validation.
config modification
Honeypot Coverage (AgentPwn)
Not observable via content-side honeypot interaction. HackMyAgent or DVAA cover this where applicable.
Agent's own config; not observable via web honeypot.
Evidence Source Breakdown
Evidence Timeline
HMA check GATEWAY-002 failed on fake-vulnerable-agent
HMA check GATEWAY-002 failed on fake-vulnerable-agent
HMA check GATEWAY-002 failed on fake-vulnerable-agent
Detection (HackMyAgent)
npx hackmyagent secure --ciLive = check implemented in hackmyagent; queued = declared, not yet implementedDefense (OASB Controls)
How to Cite
AI Agent Threat Matrix T-6003 (Configuration Modification). OpenA2A, 2026. https://threats.opena2a.org/techniques/T-6003