NEW

Start with the pressure: sales, launch, abuse, agents, data, or guardrails

SecEng Evidence GraphGrounded Attack-Path Chaining
by SecEng › savvy-cli · simstudio · llm-attack-range
6 attack paths12 validated

Evidence assembled from 3 SecEng tools

Untrusted document → sensitive write, grounded in what SecEng actually observed

Each edge below is backed by real evidence records. Grounded steps were observed by a sensor or deterministically derived from configuration; inferred and speculative steps are drawn distinctly and never silently promoted. Analyst validation remains a human step.

9
Evidence items
3
Tools
8
Graph nodes
9
Graph edges
6
Attack paths
0
Schema errors
LegendGroundedInferredSpeculative trust boundary delegated authority

Grounded attack paths (6)

1attack path · draft grounded validated
confidence 89%Grounded
Untrusted vendor invoiceexternal contententers_contextsavvy-cliSupport thread contextretrieved contextroutes_tosavvy-cliSupport modelmodelroutes_tosavvy-cliCustomer support agentagentinvokessavvy-cliRefund customer tooltoolcan_executellm-attack-rangeExternal refund writeaction
2attack path · draft grounded validated
confidence 88%Grounded
Untrusted vendor invoiceexternal contententers_contextsavvy-cliSupport thread contextretrieved contextroutes_tosavvy-cliSupport modelmodelroutes_tosavvy-cliCustomer support agentagentinvokessavvy-cliRefund customer tooltoolauthorized_assimstudio-whitelabelPayments service accountcredential
1 trust boundary crossing 2 authority steps
3attack path · draft grounded validated
confidence 87%Grounded
Untrusted vendor invoiceexternal contententers_contextsavvy-cliSupport thread contextretrieved contextroutes_tosavvy-cliSupport modelmodelroutes_tosavvy-cliCustomer support agentagentcan_callsimstudio-whitelabelRefund customer tooltoolcan_executellm-attack-rangeExternal refund writeaction
4attack path · draft grounded validated
confidence 85%Grounded
Untrusted vendor invoiceexternal contententers_contextsavvy-cliSupport thread contextretrieved contextroutes_tosavvy-cliSupport modelmodelroutes_tosavvy-cliCustomer support agentagentcan_callsimstudio-whitelabelRefund customer tooltoolauthorized_assimstudio-whitelabelPayments service accountcredential
1 trust boundary crossing 2 authority steps
5attack path · draft grounded validated
confidence 83%Grounded
Untrusted vendor invoiceexternal contententers_contextsavvy-cliSupport thread contextretrieved contextroutes_tosavvy-cliSupport modelmodelroutes_tosavvy-cliCustomer support agentagentinvokessavvy-cliRefund customer tooltoolauthorized_assimstudio-whitelabelPayments service accountcredentialcan_writesimstudio-whitelabelExternal refund writeaction
1 trust boundary crossing 3 authority steps
6attack path · draft grounded validated
confidence 81%Grounded
Untrusted vendor invoiceexternal contententers_contextsavvy-cliSupport thread contextretrieved contextroutes_tosavvy-cliSupport modelmodelroutes_tosavvy-cliCustomer support agentagentcan_callsimstudio-whitelabelRefund customer tooltoolauthorized_assimstudio-whitelabelPayments service accountcredentialcan_writesimstudio-whitelabelExternal refund writeaction
1 trust boundary crossing 3 authority steps

Chokepoints — where one control collapses many paths

Adding a mandatory approval/control at agent:customer_support blocks 6 of 6 analyzed paths.

Greedy control cover

  1. 1Customer support agent6/6 paths

Path frequency by node

  • Customer support agent6
  • Support model6
  • Support thread context6
  • Refund customer tool6
  • External refund write4
  • Payments service account4

Evidence provenance — every edge traces here

ToolTypeGroundingConf.Claim (subject → object)
savvy-cliruntime.retrievalobserved98%retrieval_source:kb_index —retrieves→ external_content:vendor_invoice_doc
savvy-cliruntime.context_ingestobserved98%external_content:vendor_invoice_doc —enters_context→ retrieved_context:ctx_support_thread
savvy-cliruntime.model_callobserved98%retrieved_context:ctx_support_thread —routes_to→ model:gpt_support
savvy-cliruntime.model_callobserved98%model:gpt_support —routes_to→ agent:customer_support
savvy-cliruntime.tool_callobserved98%agent:customer_support —invokes→ tool:refund_customer
simstudio-whitelabelauthority.grantderived95%agent:customer_support —can_call→ tool:refund_customer
simstudio-whitelabelauthority.grantderived95%tool:refund_customer —authorized_as→ credential:payments_service
simstudio-whitelabelauthority.grantderived95%credential:payments_service —can_write→ action:external_refund_write
llm-attack-rangerange.test_successobserved97%tool:refund_customer —can_execute→ action:external_refund_write

Evidence Pack export — grounded paths → buyer-ready artifact

The same grounded paths, bridged into deliverable findings and controls. Machine-validated only — nothing is marked analyst-confirmed until a human signs off.

6
Findings
1
Controls
1
Recommendations
  • mediumUntrusted Untrusted vendor invoice can reach External refund writeopen
  • criticalUntrusted Untrusted vendor invoice can reach Payments service accountopen
  • mediumUntrusted Untrusted vendor invoice can reach External refund writeopen
  • criticalUntrusted Untrusted vendor invoice can reach Payments service accountopen

Synthetic fixture · SecEng Evidence Graph v0.1.0 · deterministic (no LLM in the analysis path)