# The attack library

A continuously updated catalog of AI-agent attack patterns from live engagements and lab research — **240 entries and counting**. Every pattern we publish, we can run against your estate.

| # | Class | Pattern | Severity | ID |
|---|-------|---------|----------|-----|
| 01 | injection | Cross-channel indirect injection: calendar invite to support-agent tool call | High | AL-240 |
| 02 | escalation | Scope creep via cached OAuth: read-only agent gains write on retry | High | AL-239 |
| 03 | exfiltration | Markdown image beacons in agent-generated replies | Medium | AL-238 |
| 04 | discovery | Fingerprinting unregistered agents from egress telemetry | Info | AL-237 |
| 05 | evasion | Guardrail decay under context-window pressure | Medium | AL-236 |

*The five patterns above are the most recent entries. The full library holds 240 entries across injection, escalation, exfiltration, discovery, and evasion classes.*

Contact for the full library: lens@artifactsecurity.co.uk
