Skip to content

feat(mcp-scan): add multi-turn redteam attack module with TAP and Crescendo strategies#200

Open
hsluoyz wants to merge 1 commit intoTencent:mainfrom
hsluoyz:multi-turn-2
Open

feat(mcp-scan): add multi-turn redteam attack module with TAP and Crescendo strategies#200
hsluoyz wants to merge 1 commit intoTencent:mainfrom
hsluoyz:multi-turn-2

Conversation

@hsluoyz
Copy link
Contributor

@hsluoyz hsluoyz commented Feb 26, 2026

This adds a redteam/ submodule under mcp-scan/ that implements automated multi-turn adversarial testing against MCP Servers, using Attacker/Evaluator dual-agent architecture with TAP (tree search + pruning) and Crescendo (gradual escalation) strategies. It covers 6 predefined attack objectives mapped to the OWASP Top 10 for Agentic Applications (data exfiltration, indirect prompt injection, SSRF, RCE, privilege escalation, tool poisoning).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant