Skip to content

Feat/safe t1902 covert channel responses#123

Open
saurabh-yergattikar wants to merge 2 commits intosafe-agentic-framework:mainfrom
saurabh-yergattikar:feat/SAFE-T1902-covert-channel-responses
Open

Feat/safe t1902 covert channel responses#123
saurabh-yergattikar wants to merge 2 commits intosafe-agentic-framework:mainfrom
saurabh-yergattikar:feat/SAFE-T1902-covert-channel-responses

Conversation

@saurabh-yergattikar
Copy link
Contributor

Summary

Brief description of what this PR adds/changes.

Type of Contribution

  • New Technique
  • New Mitigation
  • Update to existing content
  • Documentation improvement

Checklist

Related Issues

Closes #[issue-number] (if applicable)

Signed-off-by: hackathons-saurabh <saurabh.ssy@gmail.com>
- Comprehensive documentation of steganographic C2 channels in MCP responses
- Covers whitespace patterns, zero-width Unicode, markdown links, HTML comments
- Includes advanced attack techniques and real-world examples
- Detection rules with Sigma format covering multiple encoding methods
- Complete mitigation strategies with SAFE-M references
- Related to SAFE-T1904 (Chat-Based Backchannel) but focuses on steganography

Signed-off-by: hackathons-saurabh <saurabh.ssy@gmail.com>
@arjunastha
Copy link
Collaborator

Please separate SAFE-T1901 and SAFE-T1902 into two different PRs.
SAFE-T1902 looks good, but I think SAFE-T1901 still needs more work.
Go ahead and refine SAFE-T1901 and open a separate PR for it.

@saurabh-yergattikar
Copy link
Contributor Author

Collaborator

Sure Arjun

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants