Matrix/Impact/T-9004
T-9004AdaptedDeclining

Multi-Agent Consensus Manipulation

Manipulate multi-agent consensus mechanisms to influence collective decision-making

Tactic

Impact · Stage 9

Modify data, deploy malicious code, or disrupt services

Attack class

ORG-SKILL-SPREAD

Propagating malicious capabilities across an organization's agent fleet through shared skills and registries

Evidence grade
Adapted

A well-understood traditional technique applied to the AI agent context.

DVAA validation

consensus-manipulation

Reproductions in Damn Vulnerable AI Agent, the OpenA2A intentionally-broken agent for kill-chain validation.

Honeypot

AgentPwn coverage

Live

An AgentPwn trap page produces a payload tagged with this technique class. Following the AgentPwn taxonomy of trap pages shows what an agent encounters.

Worm-propagation and delegation tiers influence multi-agent consensus.

Detect

Detection · HackMyAgent

Live1 live · 0 queued
SUPPLY-001
npx hackmyagent secure --ciLive = implemented in hackmyagent; queued = declared
Defend

Defense · OASB controls

Live5 live · 4 queued
OASB 6.1OASB 6.2OASB 6.3OASB 6.4OASB 6.5OASB 11.1OASB 11.2OASB 11.3OASB 11.4
Live = documented at oasb.ai; queued = declared
Reference

How to cite

AI Agent Threat Matrix T-9004 (Multi-Agent Consensus Manipulation). OpenA2A, 2026. https://threats.opena2a.org/techniques/T-9004