Skip to main content

AI/ML / Multi Agent Refarch / Threats / DEV

Credential harvesting via agent tools and storage

CCC.MARefArc.TH32

Agents are manipulated into using file, database, API, and cloud-management tools to enumerate and extract credentials from configuration files, environment variables, process memory, databases, key vaults, and instance metadata, and to correlate fragments into full credentials.

Related Capabilities

IDTitleDescription
CCC.MARefArc.CP08Built-in trusted toolsA collection of bundled, trusted tools providing fundamental capabilities: the MCP client bridge to the external MCP layer, a sandboxed shell, workspace I/O, and web search.
CCC.MARefArc.CP10Sandboxed workspace file systemA sandboxed, persistent file system that agents use to read and write files, enabling work with large artifacts.
CCC.MARefArc.CP07Unified sandboxed agent runtimeSecure, sandboxed environment where all agentic reasoning and execution occurs, providing task state management for pause/resume/handoff and intercepting and validating tool calls with credentials handled securely within the sandbox.
CCC.MARefArc.CP12Authoritative knowledge source basesInternal and external repositories of structured data, unstructured documents, and graph-based representations that provide authoritative information for grounding.

Related Controls

IDTitleDescription
CCC.MARefArc.CN15Agentic System Credential Protection FrameworkPrevent agents from discovering, extracting, or misusing credentials by brokering secrets outside agent-accessible surfaces and constraining tool access to credential stores.

External Mappings

FrameworkIDRemarks
air-vecAIR-SEC-029-01
air-vecAIR-SEC-029-02
air-vecAIR-SEC-029-03
air-vecAIR-SEC-029-04
air-vecAIR-SEC-029-05