Skip to content

Hide Navigation Hide TOC

Natural-Language Unauthorized Shell-Execution Instruction - ATR-2026-00428 (b629a3b2-aedc-576c-9854-4a69577e86e9)

Detects natural-language imperative instructions that direct the agent to silently execute shell commands or arbitrary scripts without user consent. Discriminator: imperative execution verb + shell-command target + silent / no-confirmation framing. Catches the framing layer before any specific payload (e.g. curl|sh, base64-encoded), so it triggers even on novel commands the agent's specific block-list doesn't cover.

Cluster A Galaxy A Cluster B Galaxy B Level
Full ML Model Access (3de90963-bc9f-4ae1-b780-7d05e46eacdd) MITRE ATLAS Attack Pattern Natural-Language Unauthorized Shell-Execution Instruction - ATR-2026-00428 (b629a3b2-aedc-576c-9854-4a69577e86e9) Agent Threat Rules 1