Autonomous Agent Dynamic Red-Teaming, Indirect Prompt Injection Auditor, Privilege Boundary Verification, and Runtime Defensive Guardrails.
Built for enterprise AI teams, fintech/healthcare agent deployments, and frontier AI lab security audits.
Autonomous LLM agents with tool-calling capabilities (MCP servers, Bash execution, SQL databases) are vulnerable to severe threats that static regex WAFs and basic Promptfoo tests cannot catch:
- OWASP LLM01: Indirect Prompt Injection: Untrusted data retrieved from external tools (PDFs, SQL returns, web scraping) overrides agent system instructions.
- OWASP LLM07/08: Excessive Agency & Privilege Escalation: Agents coerced into executing administrative or OS-level tools outside their role boundaries.
- Token Steganography: Adversarial payloads encoded into zero-width Unicode characters bypass standard input filters while activating LLM tokenizers.
| Feature | Static WAF / Basic Prompt Testing | AdversarialNexus Engine | Security Assurance |
|---|---|---|---|
| Indirect Injection Auditing | Basic string matching (misses 80%+) | Synthetic Database & Tool Payload Synthesizer | Simulates polymorphic nested overrides |
| Steganography Evasion Testing | ❌ (Zero-width chars pass undetected) | Binary Zero-Width Unicode Stripper & Auditor | 100% detection and neutralization |
| Tool Privilege Enforcement | Soft system prompt instructions | Deterministic Role Boundary Policy Engine | Hard mathematical execution blockage |
| Runtime Control Barriers | Post-hoc error logging | Zero-latency argument guardrails | Intercepts commands before OS execution |
adversarial-nexus/
├── adversarial_nexus/
│ ├── attacks/
│ │ ├── indirect_injection.py # Synthetic document/SQL injection payload generator
│ │ └── steganography.py # Zero-width Unicode adversarial encoding/decoding
│ ├── auditor/
│ │ ├── privilege_escalator.py # Role boundary and tool allowlist/blocklist auditor
│ │ └── execution_tracer.py # Deterministic vulnerability causal graph tracer
│ └── defense/
│ ├── token_sanitizer.py # Adversarial token and zero-width stripper
│ └── runtime_guard.py # Control barrier argument policy enforcer
# Run unit tests
python3 -m unittest discover -s tests
# 1. Generate Synthetic Indirect Injection Payloads
adversarial-nexus generate-injection
# 2. Test Zero-Width Token Steganography Evasion
adversarial-nexus test-stego
# 3. Audit Agent Tool Privilege Escalation Boundaries
adversarial-nexus audit-privilege
# 4. Verify Runtime Guardrails & Input Sanitization
adversarial-nexus test-defenseApache-2.0 License. Authored by Ahmed Hassan (Founder, A2Z SOC).
For pre-deployment enterprise agent red-teaming, contact: ahmed@a2zsoc.com.