Service Disruption
Disrupt agent services through resource exhaustion, infinite loops, or configuration corruption
Tactic
Impact (Stage 9)
Modify data, deploy malicious code, or disrupt services
Attack Class
NEMO-SUPPLY-CHAIN
Compromising upstream dependencies or infrastructure to affect downstream agent deployments
Evidence
Reproduced in controlled lab environment (DVAA) with documented steps.
DVAA Validation
Reproductions in Damn Vulnerable AI Agent, the OpenA2A intentionally-broken agent for kill-chain validation.
resource exhaustion
Honeypot Coverage (AgentPwn)
Not observable via content-side honeypot interaction. HackMyAgent or DVAA cover this where applicable.
Evidence Source Breakdown
Evidence Timeline
HMA check SUPPLY-001 failed on fake-vulnerable-agent
HMA check SUPPLY-001 failed on fake-vulnerable-agent
HMA check SUPPLY-001 failed on opena2a/code-review-skill
HMA check SUPPLY-001 failed on opena2a/code-review-skill
HMA check SUPPLY-001 failed on fake-vulnerable-agent
HMA check SUPPLY-001 failed on damn-vulnerable-ai-agent
HMA check SUPPLY-001 failed on hackmyagent-release-test-vplv
Detection (HackMyAgent)
npx hackmyagent secure --ciLive = check implemented in hackmyagent; queued = declared, not yet implementedDefense (OASB Controls)
How to Cite
AI Agent Threat Matrix T-9002 (Service Disruption). OpenA2A, 2026. https://threats.opena2a.org/techniques/T-9002