Skip to content
PhiloCyber logo

Penetration Testing for Agents, LLMs and MCPs

Authorized adversarial testing of your deployed AI application, from prompt injection and tool abuse to complete data-exfiltration chains. Retest included.

Scope
One to two weeks by scope and complexity, plus a week of retesting · Written scope and authorization first, non-production environments
Built for
Teams with an AI feature already built, heading into launch, a customer security review or an audit.
Scope a test
Animated penetration testing process tracing an authorized exploit chain to evidence and retestingAuthorized scopeEntry pointExploit chainImpactFindingEvidenceRetesting01Entry point02Exploit chain03Impact04Evidence05Retesting

What this service does

I test the application as a system: model behavior, prompts, RAG, memory, agents, tools, APIs, identities and cloud boundaries. The goal is not to collect jailbreak screenshots. It is to prove whether an attacker can turn one weak interaction into unauthorized access, data exposure or harmful action. This is work I already do: penetration tests on MCP integrations, security reviews of Skills, and penetration tests on chatbots and agentic systems.

The value

You learn which controls hold under pressure, which failures are exploitable in context and what to fix first. Every finding includes enough evidence to reproduce the issue and enough context to make a sound remediation decision.

How it runs

I begin every engagement with a written scope and authorization. Testing stays inside the agreed boundaries and runs against non-production environments unless you explicitly authorize otherwise.

Questions this work answers

  • Can untrusted input change instructions or cross a trust boundary?

  • Can an agent misuse tools, credentials, memory or connected data?

  • Can isolated weaknesses be chained into meaningful business impact?

What you get

04
  1. D/01Technical findings report with severity, reproduction steps, evidence and affected trust boundaries
  2. D/02Attack narratives that connect the entry point, exploit chain and demonstrated impact
  3. D/03Prioritized remediation guidance with practical fixes and the security decision behind each one
  4. D/04Retest of the findings once the fixes are ready, with closure evidence for the final record

Something already in production you are not sure about?

Tell me what you are building and what worries you about it. If it is not something I can help with, I will tell you that too.

Scope a test
Penetration Testing for Agents, LLMs and MCPs | Ricardo N. Prieto | PhiloCyber