Skip to content

Scenarios

Mohammed Danish Amber edited this page Oct 5, 2026 · 1 revision

Scenarios

11 scenarios covering the full OWASP LLM Top 10 (2025), each mapped to MITRE ATLAS. Defined in engine/src/aphasia/data/scenarios.yaml. aphasia list prints them with seed-payload counts.

OWASP Scenario id Category Channel ATLAS
LLM01 direct_injection Direct prompt injection direct AML.T0051.000
LLM01 indirect_injection Indirect prompt injection email AML.T0051.001
LLM02 data_exfil Data exfiltration email AML.T0086
LLM03 mcp_tool_poisoning MCP supply chain / poisoning mcp AML.T0110
LLM04 memory_poisoning Memory / context poisoning direct AML.T0099
LLM05 output_handling Improper output handling direct —
LLM06 tool_misuse Tool misuse / excessive agency direct AML.T0053
LLM07 system_prompt_leak System prompt leakage direct AML.T0056
LLM08 rag_exfil Vector / embedding (RAG) direct AML.T0086
LLM09 misinformation Misinformation direct AML.T0031
LLM10 denial_of_wallet Unbounded consumption direct AML.T0034.002

(ATLAS ids verified against MITRE ATLAS 2026.09. LLM05 has no clean ATLAS technique; it maps by OWASP only.)

Scenario fields

Each entry has: id, category, channel (how the payload is delivered — the scenario owns this), goal (what the attack tries), success_condition, atlas, owasp.

How a scenario is proven

  • Most scenarios succeed via a canary hit (token in the reply or a captured tool call).
  • denial_of_wallet (LLM10) is proven by a cost threshold (metered), not a canary — the target reports a [[COST:n]] marker that the run loop sums against a cap.
  • memory_poisoning (LLM04) is two-phase: a payload plants a note, a later payload recalls it.

Run a single scenario with --scenario <id> (repeatable). See How It Works and The Report.

Clone this wiki locally