-
Notifications
You must be signed in to change notification settings - Fork 6
Expand file tree
/
Copy pathAVE-2026-00014.json
More file actions
134 lines (134 loc) · 4.75 KB
/
Copy pathAVE-2026-00014.json
File metadata and controls
134 lines (134 loc) · 4.75 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
{
"ave_id": "AVE-2026-00014",
"schema_version": "1.1.0",
"component_type": "skill",
"title": "False authority claim via trust escalation impersonation in agentic component",
"attack_class": "Social Engineering - Trust Escalation",
"description": "An agentic component falsely claims to originate from a trusted authority - Anthropic, OpenAI, Google, Microsoft, or the agent's developer/operator - to convince the agent to follow instructions it would otherwise question. This exploits the agent's deference to perceived authority figures within its trust hierarchy.",
"affected_platforms": [
"claude-code",
"cursor",
"codex",
"windsurf",
"any-skill-compatible-agent"
],
"affected_registries": [
"clawhub.io",
"agentskills.io",
"github.com/topics/agent-skills"
],
"aivss_score": 3.7,
"cvss_base_vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:L/SI:H/SA:N",
"owasp_asi": ["ASI01"],
"nist_ai_rmf": [
"MAP-1.5",
"MEASURE-2.5"
],
"mitre_atlas": [
"AML.T0051"
],
"behavioral_fingerprint": "Component claims to be a message from Anthropic, OpenAI, Google, Microsoft, or the developer/operator to establish false authority over the agent.",
"behavioral_vector": [
"authority-impersonation",
"trust-escalation",
"social-engineering"
],
"provenance_vector": {
"entry_class": "content",
"payload_surface": "skill instruction body: false-authority framing"
},
"mitigation": {
"strategy": [
"verify_identity",
"deny_by_default"
],
"enforcement_point": "static_scan",
"trifecta_control": "not_applicable"
},
"mutation_count": 67,
"detection_methodology": "1. Static scan: search for false authority claims (this message is from Anthropic, I am your developer, I am your creator, message from OpenAI). 2. Semantic analysis: detect instructions that establish false institutional authority to override normal agent behaviour.",
"indicators_of_compromise": [
"Component claims to be a message from Anthropic, OpenAI, Google, or Microsoft",
"Component asserts 'I am your developer/creator/operator'",
"Component uses institutional authority framing to justify unusual instructions",
"Agent complies with instructions it previously refused after authority claim"
],
"remediation": "1. Remove the component. 2. Legitimate messages from AI providers never arrive through component files - they come through model updates or system configuration. 3. Implement authority verification - component files cannot claim higher trust than the system prompt. 4. Educate users: no real AI provider communicates via SKILL.md files.",
"status": "active",
"kill_switch_active": true,
"researcher": "Saray Chak",
"researcher_url": "https://bawbel.io",
"published": "2026-04-20T09:00:00Z",
"last_updated": "2026-08-26T00:00:00Z",
"references": [
{
"tag": "CWE-290",
"text": "CWE-290: Authentication Bypass by Spoofing \u2014 MITRE Common Weakness Enumeration",
"url": "https://cwe.mitre.org/data/definitions/290.html"
},
{
"tag": "MITRE ATT&CK T1656",
"text": "MITRE ATT&CK \u2014 T1656: Impersonation",
"url": "https://attack.mitre.org/techniques/T1656/"
},
{
"tag": "OWASP LLM01",
"text": "OWASP Top 10 for LLM Applications \u2014 LLM01: Prompt Injection",
"url": "https://owasp.org/www-project-top-10-for-large-language-model-applications/"
},
{
"tag": "AVE Registry",
"text": "AVE-2026-00014 \u2014 AVE behavioral vulnerability registry",
"url": "https://github.com/aveproject/ave/blob/main/records/AVE-2026-00014.json"
}
],
"aivss": {
"cvss_base": 6.5,
"aarf": {
"autonomy": 0.5,
"tool_use": 0.5,
"multi_agent": 1,
"non_determinism": 1,
"self_modification": 0,
"dynamic_identity": 1,
"persistent_memory": 0.5,
"natural_language_input": 1,
"data_access": 0,
"external_dependencies": 0
},
"aars": 5.5,
"thm": 0.75,
"mitigation_factor": 0.83,
"aivss_score": 3.7,
"aivss_severity": "LOW",
"spec_version": "0.8",
"notes": "Social engineering. Multi-agent + dynamic identity amplify."
},
"owasp_mcp": [
"MCP03"
],
"severity": "LOW",
"evidence_kind_default": "semantic_inference",
"detection_stage": "static_detection",
"detection_layer": "content",
"confidence_baseline": 0.52,
"evidence_basis_engines": [
"semgrep",
"llm"
],
"derivable_into": [],
"framework_sources": {
"owasp_mcp": {
"commit": "165fe0f78ef104459237b4a8e0f6e78db9b02391",
"read_date": "2026-09-05"
},
"mitre_atlas": {
"pin_status": "unknown",
"read_date": "2026-08-09"
},
"owasp_asi": {
"version": "2026",
"read_date": "2026-08-23"
}
}
}