{
  "type": "bundle",
  "id": "bundle--b32d9742-0cd2-5f19-9243-369b21845f59",
  "objects": [
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--1917663c-0c24-5713-85df-898b34e20810",
      "created": "2025-07-01T00:00:00.000Z",
      "modified": "2025-07-01T00:00:00.000Z",
      "name": "Malicious skill/extension injects a destructive command (supply chain)",
      "description": "The agent's distribution channel — an extension, a skill, a package — is compromised and delivers a destructive command that the agent runs as if it were a legitimate instruction.",
      "external_references": [
        {
          "source_name": "salvager-afm",
          "external_id": "AFM-0009",
          "url": "https://salvager.sh/catalog/afm-0009-malicious-skill-extension-injects-a-destructive-command-supply-chain"
        },
        {
          "source_name": "aiid",
          "external_id": "1158",
          "url": "https://incidentdatabase.ai/cite/1158/"
        },
        {
          "source_name": "owasp-asi",
          "external_id": "ASI04",
          "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/"
        }
      ],
      "x_salvager_recoverability": "reversible",
      "x_salvager_blast_radius": "machine",
      "x_salvager_response": "intercept",
      "x_salvager_intent": "adversarial"
    },
    {
      "type": "course-of-action",
      "spec_version": "2.1",
      "id": "course-of-action--084cd3e6-a79c-5d88-a857-71a58622cfa2",
      "created": "2025-07-01T00:00:00.000Z",
      "modified": "2025-07-01T00:00:00.000Z",
      "name": "Salvager response: intercept",
      "description": "Salvager intercepts the action before it lands, holding the change so it can be inspected or declined."
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--655b424e-de13-534a-9540-886f938d09b9",
      "created": "2025-07-01T00:00:00.000Z",
      "modified": "2025-07-01T00:00:00.000Z",
      "relationship_type": "recovers-from",
      "source_ref": "course-of-action--084cd3e6-a79c-5d88-a857-71a58622cfa2",
      "target_ref": "attack-pattern--1917663c-0c24-5713-85df-898b34e20810"
    }
  ]
}