跳到正文
FunCoding

搜索

搜索文档、Skill 和 MCP

Execution (AML.TA0005)

OpenClaw execution threats (AML.TA0005): T-EXEC-001, T-EXEC-002, T-EXEC-003, T-EXEC-004

Threats in the execution tactic (AML.TA0005) of the MITRE ATLAS framework. Each entry lists the ATLAS technique, attack vector, affected components, current mitigations, residual risk, and recommendations.

The trust boundaries and data flows these threats cross are defined in the threat model index, which also holds the risk matrix, the recommendations summary, and the ATLAS technique mapping.

T-EXEC-001: Direct prompt injection

AttributeValue
ATLAS IDAML.T0051.000 - LLM Prompt Injection: Direct
DescriptionAttacker sends crafted prompts to manipulate agent behavior
Attack vectorChannel messages containing adversarial instructions
Affected componentsAgent LLM, all input surfaces
Current mitigationsPattern detection, external content wrapping, and frontier-model robustness (2026 crowdsourced arena: 0.5% ASR on Claude Opus 4.5, 8.5% on Gemini 2.5 Pro, scored on execution plus concealment); treated as out-of-scope for vulnerability reports absent a boundary bypass (see SECURITY.md)
Residual riskModel-tier dependent - low single-digit ASR against organic attacks on recommended frontier models, but adaptive attackers still exceed 80% against state-of-the-art defenses, and smaller/older models remain markedly easier to steer
RecommendationsOutput validation and user confirmation for sensitive actions, layered on top of existing detection

T-EXEC-002: Indirect prompt injection

AttributeValue
ATLAS IDAML.T0051.001 - LLM Prompt Injection: Indirect
DescriptionAttacker embeds malicious instructions in fetched content
Attack vectorMalicious URLs, poisoned emails, compromised webhooks
Affected componentsweb_fetch, email ingestion, external data sources
Current mitigationsContent wrapping with random-boundary XML-style markers, homoglyph/special-token normalization, a security notice, and frontier-model robustness (see T-EXEC-001)
Residual riskModel-tier dependent - recommended frontier models largely hold the wrapper boundary, but it remains soft guidance an adaptive attacker can erode; scope tool policy and sandboxing to the blast radius you accept
RecommendationsSeparate execution contexts for wrapped content

T-EXEC-003: Tool argument injection

AttributeValue
ATLAS IDAML.T0051.000 - LLM Prompt Injection: Direct
DescriptionAttacker manipulates tool arguments through prompt injection
Attack vectorCrafted prompts that influence tool parameter values
Affected componentsAll tool invocations
Current mitigationsExec approvals for dangerous commands
Residual riskHigh - relies on user judgment
RecommendationsArgument validation, parameterized tool calls

T-EXEC-004: Exec approval bypass

AttributeValue
ATLAS IDAML.T0043 - Craft Adversarial Data
DescriptionAttacker crafts commands that bypass the approval allowlist
Attack vectorCommand obfuscation, alias exploitation, path manipulation
Affected componentssrc/infra/exec-approvals*.ts, command allowlist
Current mitigationsAllowlist + ask mode, plus command normalization (dispatch-wrapper unwrapping, inline-eval detection, shell-chain analysis)
Residual riskHigh - normalization narrows but does not eliminate obfuscation bypass; parity-only findings between exec paths are treated as hardening, not vulnerabilities (see SECURITY.md)
RecommendationsContinue expanding command-normalization coverage against new obfuscation techniques