SubTechniqueresource-developmentATLAS

AML.T0002.002AI Agent Configuration

What it is

Adversaries may acquire publicly accessible AI agent configuration files to understand agent capabilities, gain unauthorized access to tools and data sources, or identify credentials for further attacks. Configuration files define what tools an agent can use, credentials for external services, system prompts, and behavioral settings, making valuable resources for adversaries targeting AI agent deployments. Once configuration files are acquired, adversaries may perform [Discover AI Agent Configuration](/techniques/AML.T0084) to gain additional insights they can use in their operation or [Credentials from AI Agent Configuration](/techniques/AML.T0083) to harvest secrets. AI agent configuration files come in multiple forms depending on the platform and agent framework. Agent configuration files adversaries may target include: - System prompts: Files containing agent instructions, behavioral guidelines, and internal logic. - Tool configuration: Files defining tools the agent can utilize, including Model Context Protocol (MCP) configs (e.g., `mcp.json`, `claude_desktop_config.json`), IDE-specific configs (e.g., `.claude/settings.json`, `.vscode/tasks.json`), and framework-specific settings that define external tool and data source integrations. - Skills and workflows: Files defining agent capabilities, behaviors, or workflows. Often a combination of instructions, scripts, and resources. - Environment and deployment configs: Files that control agent deployment and runtime behavior, often environment variables or framework-specific configs.

References

  1. https://atlas.mitre.org/techniques/AML.T0002.002

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

ATLAS
Credentials from AI Agent Configuration
ATLAS
Discover AI Agent Configuration
ATLAS
Modify AI Agent Configuration
ATLAS
AI Agent
ATLAS
AI Agent Tool Invocation
ATLAS
Deploy AI Agent
Sourced from MITRE ATLAS — Adversarial Threat Landscape for AI Systems. Curated by Adam Lundqvist, SQUR.