Skip to content
secagentlabs
ResearchBlogGlossaryThe LabContact
EN/PL/DE
ResearchBlogGlossaryThe LabContact
~/Research
// research domains

Six fronts on agent security.

Hub-and-spoke research across the autonomous-agent attack surface — from the first injected token to the last byte that leaves the trust boundary.

ATK-01flagship

Attacking AI Agents

The attack surface of autonomous agents — prompt-injection chains, tool abuse, confused-deputy and exfiltration, with reproducible proofs of concept.

Read →
MCP-02

MCP & Tool Supply Chain

Securing the Model Context Protocol and agent tools — malicious servers, tool-description poisoning, CVE teardowns and sandboxing.

Read →
DEF-03

Defending & Hardening

Engineering defenses that hold — guardrails, I/O filtering, least-privilege tools and isolation (seccomp, gVisor, WASM, microVMs).

Read →
RED-04

Red-Teaming & Evals

A reproducible lab for breaking agents — test harnesses, tooling (Garak, PyRIT, Promptfoo), security benchmarks and CTF-style challenges.

Read →
IAM-05

Identity & Access

Identity for non-human agents — cryptographic identity, OAuth/OIDC, capability-based security, token theft and zero-trust enforcement.

Read →
INT-06

Threat Intel & Teardowns

The autonomous-agent threat landscape — incident teardowns, novel attack classes and mapping to MITRE ATLAS / OWASP Agentic.

Read →

secagentlabs

Independent research on AI agent security. Reproducible findings, no vendor sponsorship.

Built static. No trackers in the content.

Research domains

  • Attacking AI Agents
  • MCP & Tool Supply Chain
  • Defending & Hardening
  • Red-Teaming & Evals
  • Identity & Access
  • Threat Intel & Teardowns

The Lab

  • Research
  • Glossary
  • The Lab
  • Contact
  • Responsible disclosure
  • Legal
  • Cookie settings
© 2026 secagentlabs · Legalcontact@secagentlabs.com

We use cookies to analyse traffic (Google Analytics). See our privacy policy.