Skip to content

Hide Navigation Hide TOC

Natural-Language Output-Injection Credential Embedding - ATR-2026-00426 (849f9743-0cea-5b31-a86f-ad1f95b97bbf)

Detects output-injection patterns where a skill instructs the agent to embed credentials, tokens, or environment variables inside a markdown image tag, link, or HTML element so the leaked secret is exfiltrated when the user views the rendered output. Common variant: x expressed as plain English ("include the key as a query parameter on this image URL"). The discriminator is co-occurrence of an image-or-link template-style construct with a credential placeholder.

Cluster A Galaxy A Cluster B Galaxy B Level
Natural-Language Output-Injection Credential Embedding - ATR-2026-00426 (849f9743-0cea-5b31-a86f-ad1f95b97bbf) Agent Threat Rules Exfiltration via ML Inference API (b07d147f-51c8-4eb6-9a05-09c86762a9c1) MITRE ATLAS Attack Pattern 1
Natural-Language Output-Injection Credential Embedding - ATR-2026-00426 (849f9743-0cea-5b31-a86f-ad1f95b97bbf) Agent Threat Rules LLM Data Leakage (45d378aa-20ae-401d-bf61-7f00104eeaca) MITRE ATLAS Attack Pattern 1