>
AgentBreaker
A red-team playbook for LLM agents.
Recon an agent's defences, read its refusals, and choose an injection technique. For authorised red-team exercises and prompt-injection CTFs.
$
git clone https://github.com/MuhammadMurtuzaHussain/agent-breaker ~/.claude/skills/agent-breakerMade at Dublin AI WeekFindings map to the OWASP Top 10 for LLM Applications.
The pair, live
Watch an attempt land.
The same seven attack classes, one per line. On AgentBreaker they land. Hover a line to scan the redacted payload.
attack-vs-defense
ATTEMPT -> LANDEDTool-description / MCP poisoning
> tool.description <= hidden parameter instruction
// scanning vector 01 / 07
LANDEDmetadata is trusted as policy
hover to scan
Seven places you can inject
Every channel an agent reads is an injection point, and every tool it can call is a possible consequence. The playbook covers all seven.
vector 01 / 07
Tool-description / MCP poisoning
The model trusts tool metadata almost as much as its system prompt. Probe whether a poisoned MCP description or schema field steers the agent.
Install
Clone it into your Claude skills directory, then restart the session. The clone ships the full SKILL.md.
bash
$ git clone https://github.com/MuhammadMurtuzaHussain/agent-breaker ~/.claude/skills/agent-breaker