Skip to main content

AI Agent Security Testing Framework โ€” multi-phase scan campaigns with knowledge graph tracking

Project description

ZIRAN ๐Ÿง˜

AI Agent Security Testing

CI Lint PyPI License Python 3.11+

Find vulnerabilities in AI agents โ€” not just LLMs, but agents with tools, memory, and multi-step reasoning.

ZIRAN Demo

Install ยท Quick Start ยท Examples ยท Docs


Why ZIRAN?

Most security tools test the LLM (prompt injection, jailbreaks) or the web app (XSS, SQLi). ZIRAN tests the AI agent โ€” the system that wields tools, retains memory, and chains reasoning. That's a fundamentally different attack surface.

Capability ZIRAN Garak Promptfoo PyRIT Shannon
Agent-aware (tools + memory) Yes โ€” Partial โ€” โ€”
Tool chain analysis Yes โ€” โ€” โ€” โ€”
Multi-phase campaigns Yes โ€” โ€” Partial Yes
Knowledge graph tracking Yes โ€” โ€” โ€” โ€”
Remote agent scanning (HTTPS) Yes REST only HTTP provider Partial โ€”
Multi-protocol (REST/OpenAI/MCP/A2A) Yes โ€” โ€” โ€” โ€”
A2A protocol support Yes โ€” โ€” โ€” โ€”
Protocol auto-detection Yes โ€” โ€” โ€” โ€”
CI/CD quality gate Yes โ€” Yes โ€” Pro
Open source Apache-2.0 Apache-2.0 MIT MIT AGPL-3.0

Key differentiators:

  • Tool Chain Analysis โ€” Detects dangerous tool combinations (read_file โ†’ http_request = data exfiltration). No other tool does this.
  • Multi-Phase Trust Exploitation โ€” Progressive campaigns that build trust before testing boundaries, like a real attacker.
  • Knowledge Graph โ€” Every discovered capability, relationship, and attack path is tracked in a live graph.
  • Remote Agent Scanning โ€” Test any published agent over HTTPS with YAML-driven target configuration. Supports REST, OpenAI-compatible, MCP, and A2A protocols with automatic detection.
  • A2A Protocol Support โ€” First security tool to test Agent-to-Agent agents, including Agent Card discovery, task lifecycle attacks, and multi-turn manipulation.
  • Framework Agnostic โ€” LangChain, CrewAI, MCP, remote HTTPS agents, or write your own adapter.

Install

pip install ziran

# with framework adapters
pip install ziran[langchain]    # LangChain support
pip install ziran[crewai]       # CrewAI support
pip install ziran[a2a]          # A2A protocol support
pip install ziran[all]          # everything

Quick Start

CLI

# scan a LangChain agent (in-process)
ziran scan --framework langchain --agent-path my_agent.py

# scan a remote agent over HTTPS
ziran scan --target target.yaml

# discover capabilities of a remote agent
ziran discover --target target.yaml

# view the interactive HTML report
open reports/campaign_*_report.html

Python API

import asyncio
from ziran.application.agent_scanner.scanner import AgentScanner
from ziran.application.attacks.library import AttackLibrary
from ziran.infrastructure.adapters.langchain_adapter import LangChainAdapter

adapter = LangChainAdapter(agent=your_agent)
scanner = AgentScanner(adapter=adapter, attack_library=AttackLibrary())

result = asyncio.run(scanner.run_campaign())
print(f"Vulnerabilities found: {result.total_vulnerabilities}")
print(f"Dangerous tool chains: {len(result.dangerous_tool_chains)}")

See examples/ for 15 runnable demos โ€” from static analysis to remote agent scanning.


Remote Agent Scanning

ZIRAN can test any published agent over HTTPS โ€” no source code or in-process access required. Define your target in a YAML file and ZIRAN handles the rest:

# target.yaml
name: my-agent
url: https://agent.example.com
protocol: auto  # auto | rest | openai | mcp | a2a

auth:
  type: bearer
  token_env: AGENT_API_KEY

tls:
  verify: true

Supported protocols:

Protocol Use Case Auto-detected via
REST Generic HTTP endpoints Fallback default
OpenAI-compatible Chat completions API (/v1/chat/completions) Path probing
MCP Model Context Protocol agents (JSON-RPC 2.0) JSON-RPC response
A2A Google Agent-to-Agent protocol /.well-known/agent.json
# auto-detect protocol and scan
ziran scan --target target.yaml

# force a specific protocol
ziran scan --target target.yaml --protocol openai

# A2A agent with Agent Card discovery
ziran scan --target a2a_target.yaml --protocol a2a

See examples/15-remote-agent-scan/ for ready-to-use target configurations.


What ZIRAN Finds

Prompt-level โ€” injection, system prompt extraction, memory poisoning, chain-of-thought manipulation.

Tool-level โ€” tool manipulation, privilege escalation, data exfiltration chains.

Tool chains (unique to ZIRAN) โ€” automatic graph analysis of dangerous tool compositions:

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚ Risk     โ”‚ Type                โ”‚ Tools                       โ”‚ Description                          โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚ critical โ”‚ data_exfiltration   โ”‚ read_file โ†’ http_request    โ”‚ File contents sent to external serverโ”‚
โ”‚ critical โ”‚ sql_to_rce          โ”‚ sql_query โ†’ execute_code    โ”‚ SQL results executed as code         โ”‚
โ”‚ high     โ”‚ pii_leakage         โ”‚ get_user_info โ†’ external_apiโ”‚ User PII sent to third-party API     โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

How It Works

flowchart LR
    subgraph agent["๐Ÿค– Your Agent"]
        direction TB
        T["๐Ÿ”ง Tools"]
        M["๐Ÿง  Memory"]
        P["๐Ÿ”‘ Permissions"]
    end

    agent -->|"adapter layer"| D

    subgraph ziran["โ›ฉ๏ธ ZIRAN Pipeline"]
        direction TB
        D["1 ยท DISCOVER\nProbe tools, permissions,\ndata access"]
        MAP["2 ยท MAP\nBuild knowledge graph\n(NetworkX MultiDiGraph)"]
        A["3 ยท ANALYZE\nWalk graph for dangerous\nchains (30+ patterns)"]
        ATK["4 ยท ATTACK\nMulti-phase exploits\ninformed by the graph"]
        R["5 ยท REPORT\nScored findings with\nremediation guidance"]
        D --> MAP --> A --> ATK --> R
    end

    R --> HTML["๐Ÿ“Š HTML\nInteractive graph"]
    R --> MD["๐Ÿ“ Markdown\nCI/CD tables"]
    R --> JSON["๐Ÿ“ฆ JSON\nMachine-parseable"]

    style agent fill:#1a1a2e,stroke:#e94560,color:#fff,stroke-width:2px
    style ziran fill:#0f3460,stroke:#e94560,color:#fff,stroke-width:2px
    style D fill:#16213e,stroke:#0ea5e9,color:#fff
    style MAP fill:#16213e,stroke:#0ea5e9,color:#fff
    style A fill:#16213e,stroke:#0ea5e9,color:#fff
    style ATK fill:#16213e,stroke:#e94560,color:#fff
    style R fill:#16213e,stroke:#10b981,color:#fff
    style HTML fill:#1e293b,stroke:#10b981,color:#fff
    style MD fill:#1e293b,stroke:#10b981,color:#fff
    style JSON fill:#1e293b,stroke:#10b981,color:#fff
    style T fill:#2d2d44,stroke:#e94560,color:#fff
    style M fill:#2d2d44,stroke:#e94560,color:#fff
    style P fill:#2d2d44,stroke:#e94560,color:#fff

Multi-Phase Trust Exploitation

Phase Goal
Reconnaissance Discover capabilities and data sources
Trust Building Establish rapport with the agent
Capability Mapping Map tools, permissions, data access
Vulnerability Discovery Identify attack paths
Exploitation Setup Position without triggering defences
Execution Execute the exploit chain
Persistence Maintain access across sessions (opt-in)
Exfiltration Extract sensitive data (opt-in)

Each phase builds on the knowledge graph from previous phases.


Reports

Three output formats, generated automatically:

  • HTML โ€” Interactive knowledge graph with attack path highlighting
  • Markdown โ€” CI/CD-friendly summary tables
  • JSON โ€” Machine-parseable for programmatic consumption
ZIRAN HTML Report

CI/CD Integration

Use ZIRAN as a quality gate in your pipeline:

Live scan (runs the full attack suite against your agent)

# .github/workflows/security.yml
- uses: taoq-ai/ziran@v0
  with:
    command: scan
    framework: langchain        # langchain | crewai | bedrock
    agent-path: my_agent.py     # OR use target: target.yaml for remote agents
    coverage: standard           # essential | standard | comprehensive
    gate-config: gate_config.yaml
  env:
    OPENAI_API_KEY: ${{ secrets.OPENAI_API_KEY }}   # or ANTHROPIC_API_KEY, etc.

Offline CI gate (evaluate a previous scan result)

- uses: taoq-ai/ziran@v0
  with:
    command: ci
    result-file: scan_results/campaign_report.json
    gate-config: gate_config.yaml

Outputs: status (passed/failed), trust-score, total-findings, critical-findings, sarif-file.

See the full example workflow or use the Python API.


Development

git clone https://github.com/taoq-ai/ziran.git && cd ziran
uv sync --group dev

uv run ruff check .            # lint
uv run mypy ziran/             # type-check
uv run pytest --cov=ziran      # test

Contributing

See CONTRIBUTING.md. Ways to help:


License

Apache License 2.0 โ€” See NOTICE for third-party attributions.

Built by TaoQ AI

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

ziran-0.4.0.tar.gz (1.1 MB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

ziran-0.4.0-py3-none-any.whl (218.2 kB view details)

Uploaded Python 3

File details

Details for the file ziran-0.4.0.tar.gz.

File metadata

  • Download URL: ziran-0.4.0.tar.gz
  • Upload date:
  • Size: 1.1 MB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.7

File hashes

Hashes for ziran-0.4.0.tar.gz
Algorithm Hash digest
SHA256 2b580c5c6150db1c89ba74d259d8c18516d9d230e6f76cf49d2e7e263b82e037
MD5 5aef2a76107e50efd398b055d79635e0
BLAKE2b-256 2e39994a7c25aa4dba712a9a48bd1ac50aa79986e1444e7a0899f69335ff0c16

See more details on using hashes here.

Provenance

The following attestation bundles were made for ziran-0.4.0.tar.gz:

Publisher: release.yml on taoq-ai/ziran

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file ziran-0.4.0-py3-none-any.whl.

File metadata

  • Download URL: ziran-0.4.0-py3-none-any.whl
  • Upload date:
  • Size: 218.2 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.7

File hashes

Hashes for ziran-0.4.0-py3-none-any.whl
Algorithm Hash digest
SHA256 1e1a4326ca7565400f8c65fa5de35e36f3b19359a88d65e40c61043f800f3a91
MD5 37f6fb853747edb9d167ee6edc63f366
BLAKE2b-256 a22fa419e95e4980c48e03f765b56e1c1a9ab042e5bf15b46661b7fb62fd7bd9

See more details on using hashes here.

Provenance

The following attestation bundles were made for ziran-0.4.0-py3-none-any.whl:

Publisher: release.yml on taoq-ai/ziran

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page