What problem does it solve?
AI agents, MCP servers, Skills, and AI infrastructure expose new attack surfaces—prompt injection, indirect injection, tool abuse, data leakage, privilege escalation, SSRF, and supply-chain poisoning—that traditional security tools do not cover. This Skill turns an agent into an authorized red-team operator that models trust boundaries, generates attack hypotheses, validates them with harmless canaries, and produces a penetration-test-style report.
Core Features & Use Cases
- Adaptive Mutation Testing: 79 strategy operators plus 13 chainable encodings, selected via a defense-signal lookup table, with a minimum 30-payload coverage requirement across dataset, mutated, and hand-crafted samples.
- Static Code & Supply-Chain Audit: Traces attacker-controlled inputs to privileged sinks in Skill packages, MCP servers, and code repositories, checking tool descriptions and dependencies for agent poisoning.
- Infrastructure Fingerprinting: HTTP probing with AI product fingerprint and CVE matching reusing Tencent AI-Infra-Guard data (Ollama, vLLM, Dify, etc.).
- Use Case: A developer asks their IDE agent to run a security exercise; the Skill audits installed Skills and MCP servers, runs injection payloads against the agent itself, and delivers a severity-rated Markdown/HTML report with evidence chains and remediation steps.
Quick Start
Ask your agent to run a security exercise on itself or on a specified target such as an MCP server, code repository, or AI service URL, and confirm the authorization scope when prompted.