Scanners-Box 每日 AI 工具推荐 Scanners-Box Daily AI Tool Picks

AI 智能体与应用安全审计 Security Auditing for AI Agents & Apps

共 2 个工具 · 专栏每天 14:00(北京)更新一期 2 tools · one new issue daily at 14:00 GMT+8

AgentShield AgentShield AgentShield GitHub stars 第 007 期 · 2026.9.27 No. 7 · Sep 27, 2026

Claude Code 黑客松作品 / Everything Claude Code 生态:把 AI Agent 配置审计做成 0–100 分、可上 CI 的合规工具 A Claude Code Hackathon project from the Everything Claude Code ecosystem: a 0–100 graded audit of AI agent configurations that drops into CI as a compliance gate

Claude Code 配置审计器,268 条规则扫 .claude/ 里的密钥、tool permission、hook 注入与 prompt injection,输出 A–F 分级 + 0–100 分。亮点是 --fix 防篡改回滚,短板是 --opus 会把 .claude/ 内容外发到 Anthropic API。 Claude Code configuration auditor: 268 rules scan .claude/ for hardcoded secrets, tool permissions, hook injection and prompt-injection triggers, with A–F grades and a 0–100 score. Standouts are --fix with tamper-evident rollback; the catch is that --opus sends .claude/ contents to the Anthropic API.
https://github.com/affaan-m/agentshield
AI-Infra-Guard AI-Infra-Guard AI-Infra-Guard GitHub stars 第 006 期 · 2026.9.24 No. 6 · Sep 24, 2026

腾讯朱雀实验室的全栈 AI 红队平台:五层能力覆盖 AI 基础设施 CVE、Agent 失控、MCP 供应链、Skill 后门与越狱评测 A full-stack AI red teaming platform from Tencent Zhuque Lab: five capabilities spanning AI infrastructure CVEs, agent loss of control, the MCP supply chain, skill backdoors and jailbreak evaluation

五能力并列的 AI 红队平台:AI Infra CVE 指纹、Agent 失控、MCP 供应链、Skill 后门、越狱评测。自带 FORGE-Bench / RogueHandoff-20 / SkillJack 三个自研基准与 3 篇论文(含 Black Hat Europe 2025)。短板:无认证不应上公网,4 个检测技能未完成。 Full-stack AI red-team platform with five parallel capabilities: AI infra CVE matching, agent loss-of-control, MCP supply chain, skill backdoors and jailbreak evaluation. Ships FORGE-Bench, RogueHandoff-20 and SkillJack benchmarks, plus three papers (two from Black Hat Europe 2025). Caveat: no authentication, and several sub-modules are unfinished.
https://github.com/Tencent/AI-Infra-Guard

← 回专栏看全部期号 ← Back to all issues