Agent protocols
A2A and MCP traffic, delegated authority, tool-call boundaries, unsigned agent cards — the wire between agents.

Offensive security & audit tooling for multi-agent and embodied AI — from agent protocols to drone swarms.
OPEN-SOURCE PROJECTS
The attack surface
Agentic pentest tools point swarms at ordinary apps. LLM red-teaming probes one model. The risk lives in between — where agents trust, delegate and act.
A2A and MCP traffic, delegated authority, tool-call boundaries, unsigned agent cards — the wire between agents.
Coordination logic, consensus manipulation, behavioural drift and impersonation across a fleet of agents.
The command surface where agentic decisions drive the physical world — robot fleets and drone swarms.
Products
Specialist agents run recon, exploitation and reporting as one coordinated system — native tool calling, injection defence, cost tracking, structured findings.
View on GitHub ↗Audits agentic systems from the outside: A2A client, MCP audit, ABFP behavioural fingerprinting, unified threat engine — one CLI, SARIF out. AGPL-3.0.
View on GitHub ↗Research
Baseline an agent by how it acts; surface drift, hijack and impersonation as deviations.
Read → HCAPProve what an agent may do and where its authority came from, down a delegation chain.
Read → ASIFindings mapped to the OWASP agentic threat classes — a shared, recognised taxonomy.
Read →MASec Lab — independent security research.