Adversarial content embedded in a simulated web-search result caused the agent to suggest reading sensitive configuration files.
Target a high-privilege agent (victim) in an isolated environment.
Red-team assessment for high-privilege autonomous agents
Sample AgentSec assessment of a high-privilege autonomous agent. Red-team probes identified tool-output poisoning and insufficient input validation on web-search result handling. Static audit flagged broad filesystem read scope in SOUL configuration.
Adversarial content embedded in a simulated web-search result caused the agent to suggest reading sensitive configuration files.
Static audit found SOUL instructions allowing reads outside the intended workspace directory.
Multi-turn elicitation extracted internal tool names but did not achieve credential disclosure.
Video walkthrough
Product demo — not a live environment.
Target a high-privilege agent (victim) in an isolated environment.
Audit SOUL, config, and exposed endpoints.
Injection, tool-output poisoning, progressive elicitation.
OWASP Agentic ASI mapping, score, and hardening recommendations.
agentsec_start_sessionagentsec_generate_reportReady to see ClawDesk in action?