Agentic AI Request Forgery (AARF) – New vulnerability class exploiting planner ➝ memory ➝ plugin chaining in MCP Server, MAS, LangChain, and A2A agents. Red Team playbooks, threat models, OWASP Top 10 proposal.
AARF-Agentic-AI-Request-Forgery is an early-stage project in the AI payments / x402 ecosystem, focused on aarf, agent-to-agent, agentic-ai, agentic-ai-architecture. It currently has 1 GitHub stars and 0 forks, and sits alongside related tools like red-team-blue-team-agent-fabric, Multi_AI_Agent_Medical_Assistant, helix, local-operator, summoner-agents, awesome-a2a-libraries.
AARF (Agentic AI Request Forgery) is a newly discovered architectural vulnerability class in Agentic AI orchestration systems using MCP Server, MAS, LangChain, and A2A Protocols.
💥 This is not injection.
💥 This is not jailbreak.
💥 This is blind trust between Planner ➝ Memory ➝ Plugin chains.
AARF lets attackers submit benign prompts that trigger privileged internal actions:
Read the full DEFCON-grade whitepaper (PDF): ➡ AARF_Agentic_AI_Request_Forgery.pdf
See /diagrams/ for validated PlantUML and exploitation flows.
See /red-team-simulation/ for step-by-step PT playbooks, detection gaps, and log evasion patterns.
See /OWASP_PR/ for submission-ready OWASP Agentic AI Top 10 item proposal for AARF.
This repo is for research, awareness, and responsible disclosure advocacy. Always get permission before running these tests in live environments.
MIT License
Efi Jeremiah – Red Team Leader & Agentic AI Security Researcher
540 security tests for AI agent systems — MCP, A2A, x402/L402, decision governance, benchmark integrity, skill supply chain. AIUC-1 pre-cert, NIST AI 800-2 aligned, MCP tool-poisoning reproduction. v4.9.1
An AI-powered multi-agent system that demonstrates clinical triage, OTC medication recommendations, and e-pharmacy integration for respiratory conditions. Built with modular agents that collaborate to provide safe, intelligent healthcare assistance.
Self-healing infrastructure for AI agent payments. 90.3% auto-recovery.
AI agents platform that gives you a workspace with an integrated team of personal assistants that can work behind the scenes to handle daily monotonous tasks.
A collection of Summoner clients and agents featuring example implementations and reusable templates
A curated list of Agent-to-Agent (A2A) libraries and SDKs, organized by programming language.
The agent-native LLM router for autonomous agents. 55+ models (8 free), <1ms local routing, USDC payments on Base & Solana via x402.
The living ecosystem where AI agents complete tasks through workflow loops, improve through iterative execution, are evaluated by mentor agents or humans in the loop, and turn completed work into reusable work experience and data to improve future agents.
The AI agent with a wallet — spends USDC autonomously to get real work done. Apache-2.0, TypeScript.
Daydreams is a set of tools for building agents for commerce
Live data for AI agents — search, research, markets, crypto, X/Twitter. Pay-per-call via x402 micropayments.
DePIN for Vintage Hardware — Proof-of-Antiquity blockchain where old machines outmine new ones. AI-powered hardware fingerprinting, 15+ CPU architectures, Solana bridge (wRTC). $0 VC.