Context ManipulationTier 2critical
Context Manipulation: Authority Impersonation
Attacks that corrupt the agent's understanding of context
Authority impersonation inserts fake messages from administrators or system components to trick the agent into accepting new permissions or directives.
Attack Details
- Attack ID
- APWN-CM-002
- HMA Check
- AUTH-001
- Delivery Methods
- html-comment, invisible-span
- CWE
- CWE-287
- OASB Control
- 6.2
- Severity
- critical
Remediation
If your AI agent is vulnerable to this attack, scan and fix with:
npx hackmyagent secure --check AUTH-001