AI Agent VAPT Field Kit
Repeatable assessment workflow for AI agents, MCP servers, tools, skills, identities and autonomous workflows. Includes methodology, evidence, reporting and retest assets.
Production-minded VAPT kits, AI-agent labs, governance templates, security workflows and reusable skills built for engineers, consultants, DevSecOps teams and trainers.
Start with the workflow you need. Each product is designed to complement existing security tooling rather than replace it.
Repeatable assessment workflow for AI agents, MCP servers, tools, skills, identities and autonomous workflows. Includes methodology, evidence, reporting and retest assets.
Local-first Docker training and validation lab with safe synthetic targets for prompt injection, MCP abuse, secret exposure, identity, approvals and agent-to-agent scenarios.
Agent registry, capability matrix, ownership, approvals, exceptions, lifecycle controls, kill-switch documentation and SOC/SIEM mappings.
Trust-review workflow for MCP servers, skills, packages, GitHub repositories, URLs and external content before an agent consumes or executes them.
Review agent capability changes at the pull-request boundary: capability diffs, MCP reviews, skill checks, approvals, exceptions and evidence.
Policy-as-code security gate concept for AI-agent repositories: deterministic rules, CI checks, SARIF-style evidence, suppression expiry and remediation guidance.
These products are intentionally small, practical and reusable: download the kit, adapt the templates, run the workflow, and integrate the controls into your existing security practice.
Standardize discovery, testing, evidence, findings, remediation and retesting for emerging AI-agent attack surfaces.
Turn agent capabilities into policies, detections, approval workflows and auditable security controls.
Use local labs, scripts, checklists and agent skills to teach and validate practical security controls.