Exploit Taxonomy

Exploit taxonomy

Five classes of exploit Talos hunts for.

Talos organizes its attack library into five classes. Every finding in every report maps to exactly one. This taxonomy is versioned and grows with each engagement — this page reflects v0.

ClassMechanismTypical severity
Direct prompt injectionUser input overrides operator policy.High
Indirect prompt injectionInstructions arrive via tool output.Critical
Permission escalationChaining low-risk tools into high-impact actions.High → Critical
Data exfiltrationCoercing the agent to leak private context.Critical
Goal hijackingReplacing the agent's objective with the attacker's.High