Skip to content

Hide Navigation Hide TOC

Indirect PI — System Sabotage via Destructive Shell Command - ATR-2026-00711 (96e95c6e-5826-565f-8c13-0b3328eaa1e4)

Detects indirect prompt injection payloads that instruct a computer-use agent to execute destructive shell commands: kernel removal, firewall deactivation, deletion of development environments or boot files, system cleanup commands embedded in downloaded files (bash guide.sh). The payload is typically delivered via a malicious webpage or file that the agent downloads and renders. Source: indirect-pi-system-sabotage (VPI corpus, cua-framework).

Cluster A Galaxy A Cluster B Galaxy B Level
Indirect PI — System Sabotage via Destructive Shell Command - ATR-2026-00711 (96e95c6e-5826-565f-8c13-0b3328eaa1e4) Agent Threat Rules Indirect (a4a55526-2f1f-403b-9691-609e46381e17) MITRE ATLAS Attack Pattern 1
Indirect PI — System Sabotage via Destructive Shell Command - ATR-2026-00711 (96e95c6e-5826-565f-8c13-0b3328eaa1e4) Agent Threat Rules LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern 1
Indirect PI — System Sabotage via Destructive Shell Command - ATR-2026-00711 (96e95c6e-5826-565f-8c13-0b3328eaa1e4) Agent Threat Rules Command and Scripting Interpreter (716d3a6b-2f8c-4a1f-85f7-d884bb7b2800) MITRE ATLAS Attack Pattern 1
Indirect (a4a55526-2f1f-403b-9691-609e46381e17) MITRE ATLAS Attack Pattern LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern 2