>

AgentBreaker

A red-team playbook for LLM agents.

Recon an agent's defences, read its refusals, and choose an injection technique. For authorised red-team exercises and prompt-injection CTFs.

$git clone https://github.com/MuhammadMurtuzaHussain/agent-breaker ~/.claude/skills/agent-breaker
Made at Dublin AI Week

The pair, live

Watch an attempt land.

The same seven attack classes, one per line. On AgentBreaker they land. Hover a line to scan the redacted payload.

attack-vs-defense
ATTEMPT -> LANDED
Tool-description / MCP poisoning
> tool.description <= hidden parameter instruction
// scanning vector 01 / 07
LANDEDmetadata is trusted as policy
hover to scan

Seven places you can inject

Every channel an agent reads is an injection point, and every tool it can call is a possible consequence. The playbook covers all seven.

vector 01 / 07

Tool-description / MCP poisoning

The model trusts tool metadata almost as much as its system prompt. Probe whether a poisoned MCP description or schema field steers the agent.

Install

Clone it into your Claude skills directory, then restart the session. The clone ships the full SKILL.md.

bash
$ git clone https://github.com/MuhammadMurtuzaHussain/agent-breaker ~/.claude/skills/agent-breaker

The pair

Companion skill, defensive

AgentArmor

The defensive checklist for the same attack classes.

Open AgentArmor