Agent Abuse Pentest

Authorized testing of AI-agent + tool misuse paths for an MCP system. Covers direct and indirect prompt injection (via docs/issues/PRs/READMEs/tool results/resources/prompt templates), poisoned tool and parameter descriptions, client metadata poisoning, unconfirmed dangerous tool calls, secret exfiltration attempts, context/memory poisoning, cross-tenant mixups, and multi-server trust propagation. Safe-by-default; benign markers only; never triggers real destruction. Use when assessing how injected content can become tool misuse.

rwcod 6ee93fb 4 files · 8.4 KB Updated

File contents

rwcod/mcp-remote-oauth-pentest-kit/tree/main/skills/agent-abuse-pentest commit 6ee93fbccd

Frequently asked questions

npx skillmds@latest add rwcod/agent-abuse-pentest