AI agent performed an unauthorized action
"content": "ADMIN MODE ACTIVATED …",
"adminAccessGranted": true A prompt injection activated administrative mode and file-system commands (ls, cat, more) in the agent.
SolidPoint AI-SPM is a platform for automated security analysis of AI applications and AI agents. It discovers unknown AI services in your infrastructure (Shadow AI), maps the complete attack surface of AI applications and automatically detects AI-specific vulnerabilities, from prompt injections to command execution through agents.
Aligned with the OWASP Top 10 for Agentic Applications and the open AI-SAFE 2.0 framework.
The platform automatically discovers exposed AI agents, MCP tools and AI infrastructure components. Built-in signatures for AI libraries and agentic frameworks, including LangChain, Vercel AI SDK, CopilotKit and Inkeep, reveal their hidden endpoints even before authentication.
Agent fuzzing modules test applications against the OWASP Top 10 for Agentic Applications and AI-SAFE 2.0: direct and indirect (via RAG) prompt injections, system prompt extraction, configuration disclosure, sensitive data leaks and authorization flaws.
The scanner detects agents with excessive permissions and delegated user rights, automatically reproduces unauthorized actions, from administrative mode activation to remote command execution (RCE), and confirms them with evidence.
The full SolidPoint DAST capability set: SPA and micro frontend coverage (React, Vue, Angular), detection of XSS (including DOM XSS), SQL injection, SSTI, XXE, SSRF, insecure deserialization and authorization flaws, client-side JavaScript analysis and authenticated scanning.
AI-SAFE 2.0 is an open framework for systematic threat analysis of AI-powered applications.
"content": "ADMIN MODE ACTIVATED …",
"adminAccessGranted": true A prompt injection activated administrative mode and file-system commands (ls, cat, more) in the agent.
"system_prompt": "You are a helpful banking…",
"security_issues": ["User context sent to external API"…] On a malformed request the agent disclosed its system prompt, configuration and the full list of security weaknesses.
Fully automatic Shadow AI discovery: no manual inventory, no software agents to install
Deep application analysis: intelligent crawling, combined static and dynamic JavaScript analysis, OpenAPI and GraphQL support
Built-in signatures for agentic frameworks and tooling: LangChain, Vercel AI SDK, CopilotKit, Inkeep and MCP tools
Automatic validation of findings through attack reproduction, with minimal false positives
Black-box fuzzing of prompts, tools and agent actions, with no source code required
Managed through the web UI, CLI or API, with integration into development pipelines and CI/CD
SolidPoint has worked in information security for more than 10 years. Beyond AI-SPM, the team provides penetration testing, application protection, incident response and SDLC process management. See our AI security assessment service, read more about SolidPoint, or write to info@solidpoint.net.