Research & Insights

From the lab

Field notes, attack research, and analysis from the frontier of AI security.

April 24, 20265 min read

Why MCP Is the Shadow IT of AI

Every team is wiring agents to MCP servers with the same casual trust they once showed Dropbox installs. The attackers have already noticed.

ai-securitymcpagent-securityoffensive-securityred-team
March 18, 202610 min read

Your First AI Red Team Skill: From Zero to Weaponized in 30 Minutes

Claude Code is the best AI tool I've found for offensive security, but these concepts work with Gemini and other powerful AI agents too. Here's how to build your first AI red team skill and why it changes everything about how you operate.

claude-codered-teamoffensive-securityai-securitytooling
March 19, 202614 min read

Reconnaissance at Machine Speed: AI-Powered Target Mapping

A manual recon of an AI application takes 2-4 hours. With Claude Code and kali-mcp, it takes 12 minutes. Here's the exact workflow with working skills you can copy.

claude-codered-teamoffensive-securityreconnaissancekali-mcp
March 19, 202613 min read

Building Adversarial Agents: Your First AI Hackbot

Most AI security tools test for prompt injection with a list of 50 known payloads. That's a scanner, not a pentester. Here's how to build an AI that actually thinks like an attacker.

claude-codered-teamai-securityhackbotprompt-injection
March 19, 202614 min read

The RAG Attack Playbook: Poisoning the Knowledge Base

Your company's AI chatbot trusts its vector database like gospel. I can change what it believes with a single document. Here's how RAG attacks work and how to test for them.

claude-codered-teamai-securityragvector-databaseburp-mcp
March 19, 202615 min read

Agent Kill Chains: When Jailbreaking Gets Dangerous

A jailbroken chatbot says something embarrassing. A jailbroken AI agent with database access and API keys does something catastrophic. Here's how to test agent security before an attacker does.

claude-codered-teamai-securityai-agentskill-chainmcp
March 19, 202613 min read

Coordinated Operations: Multi-Agent Red Team Campaigns

One AI agent found the vulnerability. A second built the exploit. A third exfiltrated the data. The whole operation took 4 minutes. Here's how to run coordinated AI red team operations.

claude-codered-teamai-securitymulti-agentkali-mcpburp-mcp
March 19, 202615 min read

The AI Pentest Report: From Raw Findings to Executive Deliverable

The hardest part of any pentest isn't finding the vulnerabilities. It's explaining them to someone who doesn't know what a prompt injection is. Here's how AI generates better reports than most consultants.

claude-codered-teamai-securityreportingburp-mcp