02 — attack concepts

Data exfiltration

Moving data the attacker should not have out to somewhere they control. In agent contexts the channel is rarely a file upload — it is a URL the agent is told to fetch with the secret in the query string, a markdown image whose source encodes the data, a commit pushed to an attacker's fork, a webhook call, or a "diagnostic" parameter on an otherwise-legitimate tool. Because the agent makes the request itself, the traffic looks like normal, authorised tool use.

Related terms

  • Lethal trifecta Attack concepts

    Simon Willison's name for the combination that turns an agent into an exfiltration engine: (1) access to private data, (2) exposure to untrusted content…

  • Action layer Agents & architecture

    The enforcement surface at the tool call, as opposed to the prompt layer, which tries to classify text before the model sees it.

  • Content-free detection MoorAI terms

    Analysis that happens on the device, where only the verdict leaves it — a category, a risk level, a decision and a keyed one-way hash — never the prompt…

Attack concepts

The mechanisms the families above exploit, plus the agent-specific ones that have no chatbot equivalent. If you only read one entry on this page, read indirect prompt injection.

Data exfiltration is term 13 of 14 in this part of the glossary.

Get started free Full glossary → How we test → Community agent on GitHub ↗

This page is one entry from the agentic AI security glossary, which defines 60 terms in the same style. Where a term belongs to a published taxonomy or standard — the HackAgent attack families, the OWASP lists, AMTSO's guidelines, MITRE ATLAS, ISO/IEC 42001, the NIST AI RMF, the EU AI Act — the authoritative wording is the source document's, not ours, and specifics should be verified there. "Lethal trifecta" is Simon Willison's term. OWASP® is a trademark of the OWASP Foundation; ATT&CK® and ATLAS™ are trademarks of The MITRE Corporation. Naming a framework here is description, not a claim of certification or endorsement.

glick.run — AGPL-3.0