Secure AI Atlas mark Secure AI Atlas SECURITY & GOVERNANCE

Exposure and failure modes

Risk Catalogue

Observed exposure paths where generative AI connects language to data, identity, tools, permissions, or decisions before governance has enough grip.

MCP Channel Trust

The trust channel between an MCP client and server can carry malicious content, intercepted requests, or manipulated trust dialog, allowing an attacker to control agent behavior through the communication channel.

MCP agents channel trust supply chain

Agentic Supply Chain Compromise

An attacker-controlled artifact reaches an AI coding agent through plugin resolution, symlink paths, model cache, or CI trigger, and executes with the agent's privileges.

supply chain agentic AI CI/CD MCP

Excessive Agency

An AI system can take actions that exceed its reliability, authorization, or oversight model.

agents authorization human approval

Insecure Tool Invocation

AI systems call tools or APIs without sufficient validation, authorization, rate limits, or operational safeguards.

tools agents API security

Prompt Injection

Untrusted instructions enter an AI workflow and compete with the system's intended authority.

LLM trust boundary application security

Sensitive Data Disclosure

Sensitive business, personal, regulated, or secret data moves through prompts, outputs, logs, retrieval, or connected tools.

data protection privacy governance

Shadow AI

Unapproved or unknown AI use removes visibility from data handling, identity, procurement, and incident response.

visibility policy adoption