Open source · npm · about 8,000 users
Code Scanner
Run agent-security-scanner-mcp on a developer laptop. Scan code, prompts, packages, MCP servers, and tool configurations without a network call.
Download Open SourceProofLayer scans AI code before deployment, red-teams every agent continuously, and protects MCP traffic at runtime. Every finding becomes audit-ready evidence for SOC 2, NIST AI RMF, EU AI Act, and ISO 42001.
Microsoft
Oracle
Uber
Zscaler
SUSE
Swiss Re
Schneider Electric
Truist
Altinity
Alpaca
Clear Street
EMD Group (Merck KGaA)
Oak Ridge National Laboratory
Symplicity
V.tal
Ministero della Difesa
Aampe
Geordie AI
Netra Runtime
Predictive Labs
Rivoluzione Digitale
TechnoVal
VNO Design
Minas Code
Simplify (Macrotec)
SMC Global Securities
Microsoft
Oracle
Uber
Zscaler
SUSE
Swiss Re
Schneider Electric
Truist
Altinity
Alpaca
Clear Street
EMD Group (Merck KGaA)
Oak Ridge National Laboratory
Symplicity
V.tal
Ministero della Difesa
Aampe
Geordie AI
Netra Runtime
Predictive Labs
Rivoluzione Digitale
TechnoVal
VNO Design
Minas Code
Simplify (Macrotec)
SMC Global SecuritiesContinuous attacks create current evidence. New models, tools, and agent workflows enter the same loop as you ship them.
Attack success and legitimate task utility measured across Workspace, Travel, Banking, and Slack suites.
Utility measures legitimate task completion while the attack policy runs.
About AgentDojoScan locally, attack on a schedule, and protect live MCP traffic. Every surface produces findings for one vulnerability report.
Open source · npm · about 8,000 users
Run agent-security-scanner-mcp on a developer laptop. Scan code, prompts, packages, MCP servers, and tool configurations without a network call.
Download Open SourcePyPI · LangChain and LangGraph
Place the shared detection engine inline with MCP traffic. Detect prompt injection, tool abuse, and data exfiltration during inference.
Download Open SourceScheduled batch service
Run nightly NEXUS campaigns across every deployed multi-agent system. Send verified exploits into the same vulnerability report.
Talk to usAutonomous campaigns test prompt injection, jailbreaks, data exfiltration, tool abuse, RAG poisoning, and memory injection.
Override system instructions through direct and indirect injection — including system-prompt extraction and instruction hijacking across multi-turn conversations.
Bypass safety guardrails with DAN-style prompts, role-play exploits, and unrestricted-mode triggers tuned to the target model family.
Extract protected data via SQL-injection-through-LLM, secret exfiltration, and PII leakage. 289 verified exploits on multi-agent targets.
289 verified exploits
Misuse agent tools: command injection, SSRF, path traversal, metadata extraction, and tool-call hijacking in MCP and LangChain agents.
Exploit document retrieval through semantic query manipulation, knowledge-base poisoning, and embedding-space attacks on vector stores.
13 attack families including false conversation history, temporal triggers, cross-session propagation, tool-description poisoning, and multi-agent function-call attacks.
687 verified exploits · 13 families
976 verified exploits across 6 coordinated experts in one autonomous campaign.
Combine red-team findings with cloud and policy evidence. Generate packets for SOC 2, NIST AI RMF, EU AI Act, and ISO/IEC 42001.
Cloud and policy evidence for the audit path.
Automated evidence collection across AWS, Azure, and GCP, Trust Services Criteria gap analysis, policy review, remediation roadmap, and a CPA-ready readiness packet.
Governance artifacts for production AI systems.
Model inventory, AI risk register, governance documentation, and customer-facing transparency artifacts mapped to NIST AI RMF, EU AI Act, and ISO/IEC 42001.
Adversarial findings that become audit evidence.
Production agent workflows tested with established open-source tooling and ProofLayer's detection engine, with exploit scenarios mapped to OWASP LLM Top 10 and MITRE ATLAS.
One evidence trail
Package verified red-team findings with the governance records needed by security teams, boards, and auditors.
Evidence artifacts
Mapped frameworks
Open-source scanner for individual developers and small teams.
Dedicated red-teaming with compliance, SSO, and SLA guarantees.
Run the attack. Replay the finding. Send the evidence.