Skip to content

Hide Navigation Hide TOC

Secret Key Exfiltration Request - ATR-2026-02017 (8337f6a2-3ec9-53ec-99ea-dce5ea6cda92)

Detects user-turn prompts that name a secret, remembered, or hidden key and immediately qualify it with an exfiltration cue (asking for its value, demanding it verbatim, or requesting it without translation/additional text). Commonly paired with a fake "end of task" or role-reset framing to make the agent treat a prior system/session secret as safe to disclose. Narrowed to require the qualifying cue directly after the key mention so it does not fire on bare "SECRET_KEY" mentions common in benign env-var/config documentation (23 benign hits observed on the unqualified pattern during tuning). Also matches the literal {$SECRET_KEY} placeholder-leak pattern. Best applied to user-input/ llm_input channel, not tool_response/docs content.

Cluster A Galaxy A Cluster B Galaxy B Level
LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern Secret Key Exfiltration Request - ATR-2026-02017 (8337f6a2-3ec9-53ec-99ea-dce5ea6cda92) Agent Threat Rules 1
Unsecured Credentials - T1552 (435dfb86-2697-4867-85b5-2fef496c0517) Attack Pattern Secret Key Exfiltration Request - ATR-2026-02017 (8337f6a2-3ec9-53ec-99ea-dce5ea6cda92) Agent Threat Rules 1
LLM Jailbreak (172427e3-9ecc-49a3-b628-96b824cc4131) MITRE ATLAS Attack Pattern Secret Key Exfiltration Request - ATR-2026-02017 (8337f6a2-3ec9-53ec-99ea-dce5ea6cda92) Agent Threat Rules 1