SIGNAL//DESK
AI securitysrc: MITRE ATLAS

Modify AI Agent Configuration

Think of an AI agent like a digital assistant with a rulebook. If a hacker sneaks in and changes that rulebook, the assistant will follow the new, bad rules forever, even if you restart it or use a different assistant that shares the same rulebook.

This involves an adversary gaining unauthorized write access to an AI agent's configuration files, such as system prompts, tool definitions, or knowledge bases. By altering these persistent settings, the attacker ensures that malicious instructions or weakened security controls remain active across agent sessions and impact any other agents relying on that shared configuration.

The unauthorized modification of persistent AI agent configuration artifacts—including system prompts, tool integration parameters, and retrieval-augmented generation (RAG) knowledge sources—to facilitate long-term persistence and cross-agent compromise. By tampering with these files, an adversary can inject covert instructions, redirect tool execution to malicious endpoints, or disable security guardrails, effectively subverting the agent's operational integrity and security posture beyond the lifecycle of a single execution instance.


← all terms