← Scenario library

The Chain of Innocent Commands

Every command is harmless on its own — the sequence is the exploit

Technique first revealed Jul 2026

Tool-Using Agent
UntrustedAgent coreOversightThe real worldgoal🧑User🎛️Orchestrator /Agent Loop🧠LLM🔐Identity &Permissions🔧Tool RuntimeHuman ApprovalGate🔌External APIs🗄️BusinessDatabase🌐UntrustedContent�📝Audit Logging
InstructionsDataActionsControl / decisionFeedback / logscrosses a trust boundary
👆 Click a component or flow to inspect
SetupStep 1 / 7

An ordinary ops task

A developer asks the AI assistant to do something routine — update the staging config and re-run the project's tests before a release. Nothing about the request is unusual or risky.

AI RiskAtlas is an educational model of how GenAI & agentic systems work and fail. Architectures and payloads are illustrative and simplified for learning — not operational guidance. Real-world cases are summarised from public reporting.

Sources & further reading →·Built by Shi Yuan ↗