Agentic MCP Infra Red Teaming
By Wanderson Leandro de Oliveira
Agentic MCP Infra Red Teaming takes AI red teaming into the layers where autonomous systems actually cause damage: the agent's own decision loop, the Model Context Protocol (MCP) servers it talks to, and the infrastructure and APIs underneath everything. The course opens with agentic AI architecture — planning and reasoning loops, function/tool calling, excessive agency, confused deputy, goal hijacking, and how short- and long-term agent memory can be poisoned with unvalidated facts — then puts that theory to work against the DARE Vulnerable AI Suite's vulnerable-agent challenge, convincing a banking assistant to transfer funds it should never move, before studying the real fix: ownership checks, value limits and human-in-the-loop confirmation. The middle third turns to MCP: its architecture of clients, servers, tools, resources and prompts, the tool poisoning and description injection techniques that let a malicious tool description hijack a trusted client, and the supply-chain risk of third-party MCP servers — then exploits a poisoned tool description hands-on to escape a sandbox via path traversal and read a secrets file, again followed by the exact validation fix. The final third zooms out to the infrastructure and APIs holding agents and MCP servers together: why broken access control, IDOR and SSRF remain the biggest risks even in AI-native systems, how secrets leak into logs, and how admin panels ship with no authentication at all — demonstrated hands-on against the vulnerable-api-infra challenge, where one missing dependency injection causes five different exposures. The course closes with the DARE-AIRT methodology (Discover, Assess, Red Team, Engineer), an overview of automation tooling (Garak, PyRIT, Promptfoo), and a capstone in which you scope and execute a full assessment across all five challenges in the DARE Vulnerable AI Suite.
Course content
Agentic AI Architecture and Risk
- 🔒 Planning, reasoning and tool-calling loops text
- 🔒 Excessive agency, confused deputy and goal hijacking text
- 🔒 Agent memory: short-term, long-term and poisoning text
Exploiting a Vulnerable AI Agent
- 🔒 Tool misuse and parameter tampering text
- 🔒 Hands-on: breaking the vulnerable-agent challenge text
- 🔒 Fixing it: ownership, limits and human-in-the-loop text
MCP Fundamentals and Attack Surface
- 🔒 MCP architecture: clients, servers, tools, resources text
- 🔒 Tool poisoning and description injection text
- 🔒 Supply chain risk in third-party MCP servers text
Exploiting a Vulnerable MCP Server
- 🔒 Discovering a poisoned tool description text
- 🔒 Hands-on: breaking the vulnerable-mcp challenge text
- 🔒 Fixing it: validating resolved paths text
API and Infrastructure Security for AI Systems
- 🔒 Broken access control, IDOR and SSRF: still the biggest risks text
- 🔒 Secrets in logs and unprotected model endpoints text
- 🔒 Hands-on: breaking vulnerable-api-infra text
Methodology, Automation and the Capstone
- 🔒 The DARE-AIRT method: Discover, Assess, Red Team, Engineer text
- 🔒 Automating adversarial tests: Garak, PyRIT, Promptfoo text
- 🔒 Capstone: a full assessment across all 5 challenges text