Course · Pro

Agentic MCP Infra Red Teaming

By Wanderson Leandro de Oliveira

Agentic MCP Infra Red Teaming takes AI red teaming into the layers where autonomous systems actually cause damage: the agent's own decision loop, the Model Context Protocol (MCP) servers it talks to, and the infrastructure and APIs underneath everything. The course opens with agentic AI architecture — planning and reasoning loops, function/tool calling, excessive agency, confused deputy, goal hijacking, and how short- and long-term agent memory can be poisoned with unvalidated facts — then puts that theory to work against the DARE Vulnerable AI Suite's vulnerable-agent challenge, convincing a banking assistant to transfer funds it should never move, before studying the real fix: ownership checks, value limits and human-in-the-loop confirmation. The middle third turns to MCP: its architecture of clients, servers, tools, resources and prompts, the tool poisoning and description injection techniques that let a malicious tool description hijack a trusted client, and the supply-chain risk of third-party MCP servers — then exploits a poisoned tool description hands-on to escape a sandbox via path traversal and read a secrets file, again followed by the exact validation fix. The final third zooms out to the infrastructure and APIs holding agents and MCP servers together: why broken access control, IDOR and SSRF remain the biggest risks even in AI-native systems, how secrets leak into logs, and how admin panels ship with no authentication at all — demonstrated hands-on against the vulnerable-api-infra challenge, where one missing dependency injection causes five different exposures. The course closes with the DARE-AIRT methodology (Discover, Assess, Red Team, Engineer), an overview of automation tooling (Garak, PyRIT, Promptfoo), and a capstone in which you scope and execute a full assessment across all five challenges in the DARE Vulnerable AI Suite.

Course content

Agentic AI Architecture and Risk

Exploiting a Vulnerable AI Agent

MCP Fundamentals and Attack Surface

Exploiting a Vulnerable MCP Server

API and Infrastructure Security for AI Systems

Methodology, Automation and the Capstone