← AI security in plain English

AML.T0083

MITRE ATLAS / Credentials from AI Agent Configuration

Adversaries read the credentials of other tools and services out of an AI agent's configuration, where connection strings, API keys, and tokens are stored so the agent can call them.

Think of it likeOpening the assistant's address book and finding every account password written beside the contact.

In plain English

An agent needs credentials for every tool it can use, and they usually sit in one config file. Reading that file gives an attacker the whole set at once.