Open Source
Featured Projects
MCP-SandboxScan
WASM-based secure execution and hybrid analysis framework for MCP tools.
MCP-SandboxScan analyzes the behavior of LLM agent tool integrations in a sandboxed runtime. It is designed to detect risky file access, network behavior, suspicious command execution, secret exposure, and unsafe tool-server patterns.
Stack: Rust, WASM, Python, MCP, runtime tracing Focus: Agentic AI security, tool sandboxing, runtime behavior analysis Links: GitHub · Paper
MCP-Attack-Suite
Multi-vector security testing framework for MCP tool servers and LLM agent integrations.
This project evaluates how agentic systems fail under prompt injection, tool injection, multimodal manipulation, insecure coding patterns, and unsafe tool permission design.
Stack: Python, LLM evaluation, MCP, LangChain-style tool workflows Focus: AI red teaming, agent security evaluation, secure agent design Links: GitHub · Paper
SynthChain
APT-style software supply chain attack simulation framework.
SynthChain simulates realistic software and AI supply chain compromise scenarios across package ecosystems, CI/CD workflows, Docker/ML pipelines, and cloud-connected development environments.
Stack: Python, Go, NPM, Docker, CI/CD, provenance graphs Focus: Supply chain attack simulation, runtime observability, detection benchmark design Links: GitHub · Paper / Preprint