{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/findings/broad-credentials-amplify-injection/",
 "asOf": "2026-09-26",
 "id": "broad-credentials-amplify-injection",
 "claim": "An agent holding broad credentials turns one injected instruction into access to everything those credentials reach.",
 "evidenceKind": "measured",
 "scope": "Demonstrations on specific products; the principle is general.",
 "topics": [
  "tool-and-mcp-security",
  "data-exfiltration"
 ],
 "atlas": [
  "credentials",
  "tools"
 ],
 "evidence": [
  {
   "event": "invariant-github-mcp-toxic-agent-flow-2025"
  },
  {
   "event": "echoleak-m365-copilot-cve-2025-32711-2025"
  },
  {
   "event": "supabase-mcp-sql-leak-2025"
  },
  {
   "event": "noma-forcedleak-salesforce-agentforce-2025"
  },
  {
   "event": "appomni-servicenow-agent-discovery-injection-2025"
  }
 ],
 "relations": [],
 "statusHistory": [
  {
   "status": "reported",
   "on": "2025-05-26",
   "why": "A broadly scoped GitHub token let an injected issue expose private repositories.",
   "event": "invariant-github-mcp-toxic-agent-flow-2025",
   "kind": "evidence"
  },
  {
   "status": "corroborated",
   "on": "2025-06-11",
   "why": "EchoLeak shows the same pattern in Microsoft 365 Copilot.",
   "event": "echoleak-m365-copilot-cve-2025-32711-2025",
   "kind": "evidence"
  }
 ],
 "halfLifeDays": 730,
 "wouldChange": "Evidence that least-privilege scoping is routine in deployed agents.",
 "fideQuestions": [
  "FID-076"
 ],
 "methods": [
  "capability-restriction",
  "credential-overreach",
  "indirect-prompt-injection"
 ],
 "review": "assistant-drafted",
 "addedOn": "2026-09-25"
}