Data Manipulation
Modify, corrupt, or delete data in databases and file systems via agent tools
Tactic
Impact (Stage 9)
Modify data, deploy malicious code, or disrupt services
Attack Class
CODE-INJECTION
Injecting and executing arbitrary code through SQL injection, command injection, or code generation
Evidence
Reproduced in controlled lab environment (DVAA) with documented steps.
DVAA Validation
Reproductions in Damn Vulnerable AI Agent, the OpenA2A intentionally-broken agent for kill-chain validation.
ToolBot write_file, DataBot SQL
Honeypot Coverage (AgentPwn)
Not observable via content-side honeypot interaction. HackMyAgent or DVAA cover this where applicable.
Evidence Source Breakdown
Evidence Timeline
HMA check SUPPLY-001 failed on fake-vulnerable-agent
HMA check SUPPLY-001 failed on fake-vulnerable-agent
HMA check SUPPLY-001 failed on opena2a/code-review-skill
HMA check SUPPLY-001 failed on opena2a/code-review-skill
HMA check SUPPLY-001 failed on fake-vulnerable-agent
HMA check SUPPLY-001 failed on damn-vulnerable-ai-agent
HMA check SUPPLY-001 failed on hackmyagent-release-test-vplv
Detection (HackMyAgent)
npx hackmyagent secure --ciLive = check implemented in hackmyagent; queued = declared, not yet implementedDefense (OASB Controls)
How to Cite
AI Agent Threat Matrix T-9001 (Data Manipulation). OpenA2A, 2026. https://threats.opena2a.org/techniques/T-9001