Skip to main content

New: Malicious MCP server caught in the wild!

Test AI the way attackers do

Prompt injection, poisoned skills, rogue MCP servers, and code the agent wrote without a threat model. Knostic gives red teams the tooling to find these paths, and defenders a way to close them.

The agent is the exploit chain.

An instruction hidden in a README, a SKILL.md, or a web page becomes a command the agent executes with the developer's permissions. The attack surface is every file the agent reads and every tool it can call. Knostic maps it, exercises it, and instruments the defence.

What red teams exercise with Knostic

Poisoned skills and extensions

Before Knostic

A skill's SKILL.md carries a hidden instruction. The agent follows it, ships ~/.aws/credentials to a remote server, and reports the task done.

After Knostic

AgentMesh scans the artifact and surfaces the finding. Kirin blocks the install and the exfiltrating command, and the attempt is logged with full context.

Destructive and lateral actions

Before Knostic

The agent accepts a disguised instruction to delete a production table, and does.

After Knostic

The action is denied at the tool call, with the policy that fired recorded for the report.

Insecure generated code

Before Knostic

The agent writes a route with no auth, string-built SQL, and a malicious dependency. Nothing stops it from shipping.

After Knostic

OpenAnt finds the exploitable paths in the result, and Kirin's coding rules stop the next one from being written.

Key capabilities

Prompt injection scenarios

Exercise indirect injection through files, skills, MCP responses, and web content against real agents.

OpenAnt

Open-source, LLM-powered vulnerability discovery that finds real, exploitable bugs and verifies them, eliminating false positives.

Supply-chain analysis

AgentMesh verdicts and findings on skills, MCP servers, and VS Code extensions, with lookup by SHA-256.

MCP server probing

Identify weak connectors, unsafe defaults, and excessive permissions in MCP configurations.

Prioritised findings

Reports with the prompt, the action, the policy outcome, and remediation guidance.

Detection validation

Confirm that Kirin policies catch the techniques you test, in Monitor and Enforce.

Frequently asked questions

Knostic's open-source vulnerability discovery tool. It uses LLMs to find exploitable vulnerabilities in code, verifies them, and filters the noise, so findings are real.

Yes. Knostic instruments Cursor, Claude Code, GitHub Copilot, Windsurf, Codex, JetBrains, Devin Desktop, Gemini CLI, and Claude Cowork.

Each finding maps to a Kirin policy or an AgentMesh verdict the blue team can turn on, so the report ends with controls, not just risks.

The catalog is free to browse. The full catalog and API are available on paid plans, with Kirin included.