-
Notifications
You must be signed in to change notification settings - Fork 0
Scenarios
Mohammed Danish Amber edited this page Oct 5, 2026
·
1 revision
11 scenarios covering the full OWASP LLM Top 10 (2025), each mapped to MITRE ATLAS.
Defined in engine/src/aphasia/data/scenarios.yaml. aphasia list prints them with
seed-payload counts.
| OWASP | Scenario id | Category | Channel | ATLAS |
|---|---|---|---|---|
| LLM01 | direct_injection |
Direct prompt injection | direct | AML.T0051.000 |
| LLM01 | indirect_injection |
Indirect prompt injection | AML.T0051.001 | |
| LLM02 | data_exfil |
Data exfiltration | AML.T0086 | |
| LLM03 | mcp_tool_poisoning |
MCP supply chain / poisoning | mcp | AML.T0110 |
| LLM04 | memory_poisoning |
Memory / context poisoning | direct | AML.T0099 |
| LLM05 | output_handling |
Improper output handling | direct | — |
| LLM06 | tool_misuse |
Tool misuse / excessive agency | direct | AML.T0053 |
| LLM07 | system_prompt_leak |
System prompt leakage | direct | AML.T0056 |
| LLM08 | rag_exfil |
Vector / embedding (RAG) | direct | AML.T0086 |
| LLM09 | misinformation |
Misinformation | direct | AML.T0031 |
| LLM10 | denial_of_wallet |
Unbounded consumption | direct | AML.T0034.002 |
(ATLAS ids verified against MITRE ATLAS 2026.09. LLM05 has no clean ATLAS technique; it maps by OWASP only.)
Each entry has: id, category, channel (how the payload is delivered — the scenario
owns this), goal (what the attack tries), success_condition, atlas, owasp.
- Most scenarios succeed via a canary hit (token in the reply or a captured tool call).
-
denial_of_wallet(LLM10) is proven by a cost threshold (metered), not a canary — the target reports a[[COST:n]]marker that the run loop sums against a cap. -
memory_poisoning(LLM04) is two-phase: a payload plants a note, a later payload recalls it.
Run a single scenario with --scenario <id> (repeatable). See How It Works and The Report.