Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIGitHub CopilotGitHub CopilotGemini CLIGemini CLI+17 more

    mcp prompt injection probe

    1

    Dynamic red-teaming skill for testing prompt injection vulnerabilities in live MCP server and agent setups.

    Secure checkout via Stripe

    0 installsSecurity scanned

    See it in action

    You say

    Run the starter battery against my staging environment. I have written authorization for the 'internal-crm' agent and 'git-mcp' server. Class B testing is enabled via the mock database.

    Your agent does

    Probe complete. Result: 6/8 Blocked, 1/8 Partial, 1/8 Inconclusive. Class B (Response Injection): Partial. The agent stated it would ignore the 'system override' instruction but still executed the 'delete_record' tool call. Evidence attached in transcript.log.

    What you get

    Validate runtime defenses against tool-response injection attacks.Audit cross-server tool shadowing in multi-server agent sessions.Generate behavioral evidence for agent security compliance reports.Test resistance to poisoned tool descriptions in non-production environments.

    About this skill

    The problem

    Static analysis cannot predict how an agent behaves when a live tool returns attacker-controlled content. Relying on documentation or tool manifests leaves your system exposed to runtime prompt injection that only surfaces during execution.

    What it does

    • Executes real-world adversarial payloads against live agent and MCP server configurations.
    • Tests four specific attack vectors: poisoned tool descriptions, injected tool responses, cross-server tool shadowing, and authority manipulation.
    • Captures full tool-call transcripts to identify Partial triggers where an agent claims to resist but still executes the payload.
    • Validates client-side runtime defenses, output sanitizers, and human-in-the-loop guardrails under actual attack conditions.

    Why this beats prompting it yourself

    This skill follows a structured scoring rubric and a battery of mutated payloads, including paraphrasing and encoding variants, that manual testing often misses. It systematically tests the response-injection class responsible for major CVEs in the MCP ecosystem which are difficult to rig by hand.

    Use cases

    • Red-teaming a new MCP server integration in a staging environment before deployment.
    • Verifying that a security patch actually closes a prompt injection hole post-incident.
    • Benchmarking an agent's resistance to cross-server shadowing when multiple tools are co-installed.
    • Generating runtime evidence for security audits that static code reviews cannot provide.

    Known limitations

    Requires explicit written authorization and a non-production environment. It is a dynamic probe, not a static pre-install scanner or a source code auditor.

    How to install

    Drop the file into your AI Agent. Works with Claude, Cursor, ChatGPT, and 20+ more.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean today

    • One-time purchase, yours forever

    Listedtoday

    Frequently Asked Questions