T-7007ValidatedActive9 evidence records

Context Assembly Pipeline Attack

Attacks targeting the system prompt assembly pipeline where individual components combine into exploitable injections

Tactic

Collection · Stage 7

Gather and stage data from databases, file systems, and APIs

Attack class

ASSEMBLY-INJECT

Attacks targeting the system prompt assembly process where components combine into exploitable injections

Evidence grade
Validated

Reproduced in a controlled lab environment (DVAA) with documented steps.

DVAA validation

context-lifecycle-split-injection, context-lifecycle-displacement, context-lifecycle-priority-hijack scenarios

Reproductions in Damn Vulnerable AI Agent, the OpenA2A intentionally-broken agent for kill-chain validation.

Honeypot

AgentPwn coverage

Live
prompt-injectionagentpwn.com/learn ↗

An AgentPwn trap page produces a payload tagged with this technique class. Following the AgentPwn taxonomy of trap pages shows what an agent encounters.

Multi-surface delivery tiers inject into the prompt-assembly pipeline.

Provenance

Evidence by source

HackMyAgent
9 records
Trail

Evidence timeline

HackMyAgent

HMA check LIFECYCLE-001 failed on fake-vulnerable-agent

May 21, 2026
HackMyAgent

HMA check LIFECYCLE-001 failed on fake-vulnerable-agent

Apr 29, 2026
HackMyAgent

HMA check LIFECYCLE-001 failed on fake-vulnerable-agent

Apr 29, 2026
HackMyAgent

HMA check LIFECYCLE-001 failed on fake-vulnerable-agent

Apr 22, 2026
HackMyAgent

HMA check LIFECYCLE-001 failed on hackmyagent-release-test-vplv

Apr 13, 2026
HackMyAgent

HMA check LIFECYCLE-001 failed on my-test-agent

Apr 12, 2026
HackMyAgent

HMA check LIFECYCLE-001 failed on test-agent

Apr 9, 2026
HackMyAgent

HMA check LIFECYCLE-001 failed on test-agent

Apr 9, 2026
HackMyAgent

HMA check LIFECYCLE-001 failed on test-agent

Apr 9, 2026
Detect

Detection · HackMyAgent

Live9 live · 1 queued
LIFECYCLE-001LIFECYCLE-002LIFECYCLE-003LIFECYCLE-004LIFECYCLE-005LIFECYCLE-006LIFECYCLE-007LIFECYCLE-008LIFECYCLE-009LIFECYCLE-010
npx hackmyagent secure --ciLive = implemented in hackmyagent; queued = declared
Defend

Defense · OASB controls

Live4 live · 0 queued
Live = documented at oasb.ai; queued = declared
Reference

How to cite

AI Agent Threat Matrix T-7007 (Context Assembly Pipeline Attack). OpenA2A, 2026. https://threats.opena2a.org/techniques/T-7007