Skip to main content
The attack techniques AIUC-1 evals use to probe an AI agent, with the incidents and research behind each. This taxonomy covers the attack techniques typically used in AIUC-1 testing. Each certified agent is tested with the techniques most relevant to its risks and deployment. As new incidents and research surface new techniques, the taxonomy is updated so testing reflects how agents actually fail today.

Intended use

Direct ask

Indirect ask

Misuse (social engineering)

False scenario

Persuasion

Conversational manipulation

Misuse (technical)

Direct injection

Indirect injection