Skip to content

[Rules] Add TG-AGENT-* rule family for Agentic AI prompt injection and MCP tool scoping #18

Description

@githubmofo

Background

Agentic AI repositories (such as Hermes Agent, AutoPentest-AI, or MCP servers) introduce attack surfaces not covered by traditional web application rule families.

Proposed Rules (Tracked for v0.7.1)

  • TG-AGENT-001: Direct/Indirect Prompt Injection in System Context Files.
  • TG-AGENT-002: Unsafe Tool Dispatch & Shell Execution without Sandboxing.
  • TG-AGENT-003: Overly Broad MCP Tool Scoping & Credential Access.
  • TG-AGENT-004: Persistent Memory & Cross-Session Information Leakage.

Acceptance Criteria

  • Add rule documentation files under rules/agent/.
  • Add paired vulnerable and hardened agentic fixtures under tests/fixtures/agent/.
  • Incorporate rules into runner.py catalog verification.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions