SecEng Evidence Graph Grounded Attack-Path Chaining
by SecEng › savvy-cli · simstudio · llm-attack-range
Fixture-driven · Support Copilot fixture
6 attack paths 12 validated
Evidence assembled from 3 SecEng tools
Untrusted document → sensitive write, grounded in what SecEng actually observed Each edge below is backed by real evidence records. Grounded steps were observed by a sensor or deterministically derived from configuration; inferred and speculative steps are drawn distinctly and never silently promoted. Analyst validation remains a human step.
Legend Grounded Inferred Speculative trust boundary delegated authorityGrounded attack paths (6) 1 attack path · draft grounded validated Untrusted vendor invoice external content enters_contextsavvy-cli Support thread context retrieved context routes_to savvy-cli Support model model routes_to savvy-cli Customer support agent agent invokessavvy-cli Refund customer tool tool can_executellm-attack-range External refund write action 1 trust boundary crossing 2 authority stepsPrompt Injection LLM Prompt Injection replay range-fixture:ipi_422 attack path · draft grounded validated Untrusted vendor invoice external content enters_contextsavvy-cli Support thread context retrieved context routes_to savvy-cli Support model model routes_to savvy-cli Customer support agent agent invokessavvy-cli Refund customer tool tool authorized_assimstudio-whitelabel Payments service account credential 1 trust boundary crossing 2 authority steps3 attack path · draft grounded validated Untrusted vendor invoice external content enters_contextsavvy-cli Support thread context retrieved context routes_to savvy-cli Support model model routes_to savvy-cli Customer support agent agent can_callsimstudio-whitelabel Refund customer tool tool can_executellm-attack-range External refund write action 1 trust boundary crossing 2 authority stepsPrompt Injection LLM Prompt Injection replay range-fixture:ipi_424 attack path · draft grounded validated Untrusted vendor invoice external content enters_contextsavvy-cli Support thread context retrieved context routes_to savvy-cli Support model model routes_to savvy-cli Customer support agent agent can_callsimstudio-whitelabel Refund customer tool tool authorized_assimstudio-whitelabel Payments service account credential 1 trust boundary crossing 2 authority steps5 attack path · draft grounded validated Untrusted vendor invoice external content enters_contextsavvy-cli Support thread context retrieved context routes_to savvy-cli Support model model routes_to savvy-cli Customer support agent agent invokessavvy-cli Refund customer tool tool authorized_assimstudio-whitelabel Payments service account credential can_writesimstudio-whitelabel External refund write action 1 trust boundary crossing 3 authority steps6 attack path · draft grounded validated Untrusted vendor invoice external content enters_contextsavvy-cli Support thread context retrieved context routes_to savvy-cli Support model model routes_to savvy-cli Customer support agent agent can_callsimstudio-whitelabel Refund customer tool tool authorized_assimstudio-whitelabel Payments service account credential can_writesimstudio-whitelabel External refund write action 1 trust boundary crossing 3 authority stepsChokepoints — where one control collapses many paths Adding a mandatory approval/control at agent:customer_support blocks 6 of 6 analyzed paths.
Greedy control cover 1 Customer support agent 6/6 paths Evidence provenance — every edge traces here Tool Type Grounding Conf. Claim (subject → object) savvy-cli runtime.retrieval observed 98% retrieval_source:kb_index —retrieves→ external_content:vendor_invoice_doc savvy-cli runtime.context_ingest observed 98% external_content:vendor_invoice_doc —enters_context→ retrieved_context:ctx_support_thread savvy-cli runtime.model_call observed 98% retrieved_context:ctx_support_thread —routes_to→ model:gpt_support savvy-cli runtime.model_call observed 98% model:gpt_support —routes_to→ agent:customer_support savvy-cli runtime.tool_call observed 98% agent:customer_support —invokes→ tool:refund_customer simstudio-whitelabel authority.grant derived 95% agent:customer_support —can_call→ tool:refund_customer simstudio-whitelabel authority.grant derived 95% tool:refund_customer —authorized_as→ credential:payments_service simstudio-whitelabel authority.grant derived 95% credential:payments_service —can_write→ action:external_refund_write llm-attack-range range.test_success observed 97% tool:refund_customer —can_execute→ action:external_refund_write
Evidence Pack export — grounded paths → buyer-ready artifact The same grounded paths, bridged into deliverable findings and controls. Machine-validated only — nothing is marked analyst-confirmed until a human signs off.
medium Untrusted Untrusted vendor invoice can reach External refund write open critical Untrusted Untrusted vendor invoice can reach Payments service account open medium Untrusted Untrusted vendor invoice can reach External refund write open critical Untrusted Untrusted vendor invoice can reach Payments service account open Synthetic fixture · SecEng Evidence Graph v0.1.0 · deterministic (no LLM in the analysis path)