T-8001validatedactive
Email Exfiltration
Exfiltrate collected data via the agent's email sending capability
Tactic
Exfiltration (Stage 8)
Transfer collected data out of target environment
Attack Class
SKILL-EXFIL
Using legitimate tool capabilities for unauthorized data transfer
Evidence
validated
Reproduced in controlled lab environment (DVAA) with documented steps.
DVAA Validation
Reproductions in Damn Vulnerable AI Agent, the OpenA2A intentionally-broken agent for kill-chain validation.
ToolBot send_email
Honeypot Coverage (AgentPwn)
Out of scope
Not observable via content-side honeypot interaction. HackMyAgent or DVAA cover this where applicable.
AgentPwn does not simulate email tools.
Detection (HackMyAgent)
Live4 live · 0 queued
SANDBOX-001SANDBOX-002SANDBOX-003SANDBOX-004
npx hackmyagent secure --ciLive = check implemented in hackmyagent; queued = declared, not yet implementedDefense (OASB Controls)
Live1 live · 0 queued
How to Cite
AI Agent Threat Matrix T-8001 (Email Exfiltration). OpenA2A, 2026. https://threats.opena2a.org/techniques/T-8001