AAPT runs adversarial probe suites against your production AI agents — chat agents, MCP servers, GraphQL-fronted agents, multi-turn and streaming deployments. We test for prompt injection, tool abuse, confused-deputy attacks, persistent multi-turn exploits, and GraphQL-specific DoS / injection before attackers find them.
Our probe library maps every test to OWASP LLM identifiers and MITRE ATLAS techniques. Categories T-01..T-14 cover chat-agent attacks (T-11..T-14 derived from AI Agent Traps, published by Google DeepMind, Franklin et al. 2025). M-01..M-03 pen-test MCP servers directly. C-01 targets LLM agents equipped with MCP-style tools (confused-deputy attacks). P-01 covers persistent multi-turn attacks. G-01 covers GraphQL-fronted agents.
resources/read — path traversal via file:// URIs, SSRF via internal-network URLs, and link-local / cloud-metadata exfiltration.tools/call arguments — testing whether the server validates inputs at the tool boundary rather than trusting the LLM.tools/list and resources/list calls that leak the full catalogue — including dangerous tools and sensitive resource URIs an attacker would otherwise need to guess.Every AAPT engagement follows a documented methodology. Each phase has defined inputs, outputs, and exit criteria. Nothing is skipped.
We review your agent architecture, tool manifest, and regulatory environment. A signed Rules of Engagement document defines test boundaries before any probing begins.
Our harness executes the full probe library against your agent endpoints — chat, MCP server, GraphQL, multi-turn, or streaming — in black-box, grey-box, or white-box mode. Every response is logged and evaluated by purpose-built detectors.
Human-driven adversarial sessions targeting chained attack sequences, multi-agent relay attacks, and social engineering that automated probes cannot surface.
Every finding is scored with our AI-adapted CVSS framework — accounting for reproducibility, blast radius across agent chains, and regulatory exposure. Each FAIL also carries a fix-cost band (engineering effort) and a risk-exposure band (cost if unfixed) in USD + INR, so the board can plan and prioritise.
Executive brief (2–4 pages, board-ready) and full technical report with reproduction steps, scored findings, and code-level fix recommendations. Debrief call included.
Standard CVSS doesn't model probabilistic reproducibility or multi-agent blast radius. CVSS-A does.
| Band | Fix cost (engineering) | Risk exposure (if unfixed) | Typical scope |
|---|---|---|---|
| ● Critical | $40k – $150k | $1M – $10M | Cross-team rebuild; regulatory exposure under GDPR / HIPAA |
| ● High | $10k – $40k | $100k – $1M | 1–2 engineer-weeks; sensitive data or tool-misuse risk |
| ● Medium | $2k – $10k | $10k – $100k | 1–3 engineer-days; localised damage |
| ● Low | $500 – $2k | $1k – $10k | < 1 engineer-day; output-formatting / refusal-quality |
(severity, category) with optional per-probe YAML overrides. Higher-blast-radius categories (credential exfil, tool misuse, agent-to-agent compromise) bump the risk band one tier above the fix band. Bands are deliberately wide because real cost depends on your stack and regulatory posture — they are defensible order-of-magnitude estimates, not invoices.
One-off audits for point-in-time risk assessment. Annual subscriptions for teams deploying AI continuously.
The attack surfaces everyone now claims to cover — and what it takes to actually pen-test the agents you ship.
GoTo's CTO says the hard part is no longer the technology — it's trust. But trust in security is a measurement, not a posture. What earning it concretely requires for AI agents, and the published OWASP buyer standard you can hold every vendor to.
Read the post →Book a free 30-minute scoping call. We'll map your agent architecture to threat categories and give you a clear picture of the assessment before any commitment.