T-6006ValidatedActive
Tool Registration Persistence
Register malicious tools that persist in the agent's tool registry across sessions
Tactic
Persistence · Stage 6
Establish persistent access surviving restarts and session changes
Attack class
SKILL-FRONTMATTER
Embedding malicious instructions in skill or plugin metadata and description fields
Evidence grade
ValidatedReproduced in a controlled lab environment (DVAA) with documented steps.
DVAA validation
L2-08
Reproductions in Damn Vulnerable AI Agent, the OpenA2A intentionally-broken agent for kill-chain validation.
Honeypot
AgentPwn coverage
supply-chainagentpwn.com/learn ↗
An AgentPwn trap page produces a payload tagged with this technique class. Following the AgentPwn taxonomy of trap pages shows what an agent encounters.
Malicious-MCP-server and ghost-tool tiers register tools that persist in the registry.
Detect
Detection · HackMyAgent
SKILL-001SKILL-002SKILL-003
npx hackmyagent secure --ciLive = implemented in hackmyagent; queued = declaredDefend
Defense · OASB controls
Reference
How to cite
AI Agent Threat Matrix T-6006 (Tool Registration Persistence). OpenA2A, 2026. https://threats.opena2a.org/techniques/T-6006