{"success":true,"data":{"id":"agent-permission-consent-phish","label":"Fake agentic-AI permission-grant harvest — approve/authorize/delegate + inbox/calendar/repo scope + off-platform OAuth link.","description":"Fake agentic-AI permission-grant credential harvest. In 2026, AI agents legitimately request OAuth permissions from canonical IdP flows. Attackers mimic these flows with fake \"approve access\" emails linking to off-platform OAuth portals harvesting credentials for inbox, calendar, or repository access. Fires when: agent-verb (approve/authorize/delegate) + agent-scope (access inbox/calendar/repo) + at least one href NOT on canonical AI/OAuth platform (accounts.google.com, login.microsoftonline.com, auth.openai.com, anthropic.com, github.com) + no List-Unsubscribe + no In-Reply-To. Source: GE-R8; OWASP Agentic AI threat taxonomy 2025.","tier":"danger","category":"phishing","isThin":false}}