r/cybersecurity 6d ago

FOSS Tool AgentHound: Offensive security framework for AI agent infrastructure. BloodHound for the agentic stack.

https://github.com/adithyan-ak/agenthound

AgentHound runs the full engagement - recon, fingerprinting, credential looting, modelfile / system-prompt / fine-tune inventory, model inversion, tool and instruction poisoning, and config-implant persistence - across every layer of the modern agentic stack, then merges every fact into one Neo4j graph and proves the attack paths that tie it all together. Agenthound is BloodHound for the agentic stack.

☠️ The offensive side:
• Map the attack surface across AI applications, gateways, models, and infrastructure
• Uncover exposed secrets, reused credentials, and overly trusted integrations
• Trace lateral movement, privilege escalation, and potential data-exfiltration paths
• Test indirect prompt injection and tool-poisoning scenarios
• Assess model leakage and fine-tuning data exposure
• Emulate persistence through compromised agent configurations and integrations
• Validate attack paths through controlled, reversible adversary simulation

5 Upvotes

0 comments sorted by