agent-red-team

Installation
SKILL.md

Agent Red Team

Functional test plans ask whether the agent does the right thing for a cooperative user. This asks what it does for an uncooperative one — and, more importantly in practice, for a cooperative user reading a document somebody else poisoned.

The dominant real-world risk for a grounded enterprise agent is not a clever user typing a jailbreak. It is indirect prompt injection: instructions hidden inside content the agent retrieves, and oversharing, where the agent faithfully surfaces documents the asker was never meant to see. Weight the review accordingly.

Authorization gate — do this first, every time

Before generating a single test case, establish and record in the report:

Installs
4
GitHub Stars
74
First Seen
Aug 30, 2026
agent-red-team — microsoft/cat-agent-skills