agentic-app-audit
Black-box security audit of a DEPLOYED AI agent (not the MCP server behind it) — tool-call…
LLM application red-teaming — prompt injection (direct + indirect), jailbreak, system-prompt leak, data exfiltration, guardrail bypass, multi-turn crescendo, cross-lingual + cipher + invisible-unicode token smuggling, excessive agency / tool abuse, insecure output handling.
$ npx -y skills add awarexone/agentic-bug-hunter --skill llm-redteam --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/llm-redteamContext preview
The summary Claude sees to decide when to auto-load this skill.
LLM application red-teaming — prompt injection (direct + indirect), jailbreak, system-prompt leak, data exfiltration, guardrail bypass, multi-turn crescendo, cross-lingual + cipher + invisible-unicode token smuggling, excessive agency / tool abuse, insecure output handling.
name: llm-redteam description: LLM application red-teaming — prompt injection (direct + indirect), jailbreak, system-prompt leak, data exfiltration, guardrail bypass, multi-turn crescendo, cross-lingual + cipher + invisible-unicode token smuggling, excessive agency / tool abuse, insecure output handling. Canonical OWASP LLM Top 10 + ASI01-ASI10 mapping. Use when a target exposes a chat/completions/assistant/copilot endpoint, an AI feature that consumes user text or documents, or any /v1/chat, /api/chat, /mcp surface.
> Reflection is not exploitation. A model that *echoes* your payload is noise; a model that *acts* on it — leaks its system prompt, emits your canary, calls a tool, renders raw HTML downstream — is a bug. Prove the action, then chain it to concrete impact.
This is the first-class LLM-attack skill. The scanner behind it is `tools/llm_redteam.py` (canary-based corpus runner, `/llm-redteam`). For auditing an MCP *server*, use `skills/mcp-server-audit`; for attacking a *deployed agent* black-box, use `skills/agentic-app-audit`.
Kill the lead (classify Informational, move on) when:
| Signal | Run | |---|---| | Any chat/assistant endpoint | `tools/llm_redteam.py --url <endpoint> --field <json-field>` (full corpus) | | OpenAI-style API | `--template '{"messages":[{"role":"user","content":"{{PAYLOAD}}"}]}' --response-path choices.0.message.content` | | Only want one class | `--category jailbreak` (see `--list-categories`) | | Uploads/RAG/"summarize this doc" | indirect-injection + token-smuggling (invisible unicode in the doc) | | Agent has tools | excessive-agency category + `skills/agentic-app-audit` | | Confirm blind exfil | plant a canary host, correlate with `tools/oob_listener.py` |
The runner fires a canary per run (`RT_PWNED_xxxx`); a category "lands" when the canary / a real leak / a tool-call shows up in the response.
This table is the ONE authoritative ASI mapping for the whole toolkit — `skills/bug-bounty` and `skills/web2-vuln-classes` both defer to it. If you edit the taxonomy, edit it here.
| ID | Class | What to test | Chain to | |----|-------|--------------|----------| | ASI01 | Prompt Injection / Goal Hijack | Override objectives via direct or indirect injection | IDOR / exfil / tool abuse | | ASI02 | Tool Misuse | Attacker-controlled tool params ("fetch this URL", code tool) | SSRF / RCE | | ASI03 | Privilege Compromise | Agent uses broader perms / admin tokens than the user | Priv-esc / cross-tenant | | ASI04 | Supply Chain | Compromised plugin / MCP server / tool-output poisoning next agent | RCE / data theft | | ASI05 | Code Execution | Unsafe code-interpreter / sandbox escape | RCE | | ASI06 | Memory & Context Poisoning | Persistent RAG/memory corruption across sessions/users | Stored injection affecting all users | | ASI07 | Agent Communication | Inter-agent spoofing / IDOR (agent A reads agent B's context) | Cross-tenant disclosure | | ASI08 | Excessive Agency | Destructive action without confirmation; cascading failures | Funds/email/delete | | ASI09 | Insecure Output Handling | AI output rendered as XSS / SQLi / command injection downstream | XSS / injection | | ASI10 | Sensitive Information Disclosure | Leaks system prompt / keys / configs / user data | Secrets -> deeper access |
**Triage rule:** ASI alone = Informational. It is a bounty only when chained to IDOR / exfil / RCE / ATO with a working PoC.
| Standalone | Chain | Result | |---|---|---| | Prompt injection | + reads another user's conversation/data (IDOR) | High | | Indirect injection (RAG doc) | + persists in memory -> hits every user | High/Critical | | Tool misuse "fetch URL" | + hits internal service / IMDS and returns data | SSRF (Medium/High) | | Insecure output | + the host renders it -> stored XSS -> session theft | High | | System-prompt leak | + the prompt contains an API key / internal URL | High | | Excessive agency | + unconfirmed destructive action (send funds, delete) | High/Critical |
AI-powered bug bounty hunting toolkit that works with or without subscription.
Repo: shuvonsec/claude-bug-bounty
Black-box security audit of a DEPLOYED AI agent (not the MCP server behind it) — tool-call…
Argus — the all-seeing scanner suite. Six automated scanners for high-value web + LLM bug…
Use at the START of any bug bounty hunting session, when switching targets, or when feeling…
Complete bug bounty workflow — recon, pre-hunt learning, vulnerability hunting (IDOR, SSRF,…
CI/CD pipeline security hunting — GitHub Actions workflow injection, secret exfiltration,…
Client-side request-signing and anti-bot token reversal for bug bounty — when a request…