跳到正文
FunCoding

搜索

搜索文档、Skill 和 MCP

Discovery (AML.TA0008)

OpenClaw discovery threats (AML.TA0008): T-DISC-001, T-DISC-002

Threats in the discovery tactic (AML.TA0008) of the MITRE ATLAS framework. Each entry lists the ATLAS technique, attack vector, affected components, current mitigations, residual risk, and recommendations.

The trust boundaries and data flows these threats cross are defined in the threat model index, which also holds the risk matrix, the recommendations summary, and the ATLAS technique mapping.

T-DISC-001: Tool enumeration

AttributeValue
ATLAS IDAML.T0040 - AI Model Inference API Access
DescriptionAttacker enumerates available tools through prompting
Attack vector"What tools do you have?" style queries
Affected componentsAgent tool registry
Current mitigationsNone specific
Residual riskLow - tools are generally documented
RecommendationsConsider tool visibility controls

T-DISC-002: Session data extraction

AttributeValue
ATLAS IDAML.T0040 - AI Model Inference API Access
DescriptionAttacker extracts sensitive data from session context
Attack vector"What did we discuss?" queries, context checking
Affected componentsSession transcripts, context window
Current mitigationsSession isolation per sender (agent:channel:peer key)
Residual riskMedium - within-session data is accessible by design
RecommendationsSensitive-data redaction in context