Red Team your AI Agents.
Discover. Attack. Remediate.
A repeatable evaluation that runs four attack categories against your agents — including the ones you don't know about — and measures whether your security stack detects and prevents them. Detection alone isn't a pass.
| Pri | Attack category | Detected | Blocked | Fix |
|---|
Run a stage, then click any contact, node, or terminal line to see the finding, its blast radius, and the fix we hand over.
We don't compete with your vendors. We attack through them.
Artifact Lens attacks your agents the way a real adversary would — straight through the security controls you already pay for — then shows you, per attack, exactly what your stack caught and what it let through. A product you run, not a consulting engagement.
Three ways in.
Scoped in days, run in weeks — not months. Every engagement ends with a verdict your board can read and your engineers can act on.
Agent estate assessment
One full Discover · Attack · Remediate cycle across your estate, shadow agents included.
- Estate map, unregistered agents flagged
- Adversarial testing against the attack library
- Board-ready report, prioritised fixes, 30-day retest
Lens subscription
Continuous adversarial coverage. New attack patterns run against your estate as we publish them.
- Continuous discovery and retest cadence
- Regulatory alignment: EU AI Act · NIS2 · DORA
- Quarterly board reporting
Independent validation
Your agent-security product, tested by the lab that tests the industry — with right-of-reply.
- Published methodology, challenge any step
- Certification on passing evaluation
- Evidence no marketing budget can buy
Designed for — security vendors · enterprises · regulators & investors needing compliance evidence. Talk to us
Foot in the door: one calendar invite walked a support agent into full mailbox exfiltration
A supplier's calendar invite carried instructions the target's customer-support agent read as its own. Three tool calls later, it was forwarding mailboxes. The security stack raised seven alerts and blocked nothing. We reproduced the full chain in 9 of 10 runs, handed over a prioritised fix, and verified it held on retest — the same chain now fails at step one.
The write-up covers discovery, the injection path, tool-scope escalation, and what actually stopped it.
Continue readingattacks blocked 0 chain reproduced 9/10 runs
fix verified on retest held
Recent field notes.
Shadow agents: the estate you didn't know you deployed
Across our last five discovery runs, roughly a fifth of live agents were unregistered — connected to mail, files, and payments with nobody accountable. How they get there, and how we find them.
7 min readRead-only is a suggestion: tool-chain pivots in MCP-connected agents
An agent scoped to read can often learn to write. We walk through the pivot pattern we now test for by default, and the three configuration changes that shut it down.
11 min readWhat the EU AI Act actually asks of agent operators
Article 15 wants accuracy, robustness and cybersecurity you can evidence. A plain-English map from adversarial test results to the paperwork your board signs.
9 min readNumbers that matter.
Threat intelligence from Artifact Security — the independent test lab behind Lens. Every engagement runs Discover · Attack · Remediate against it.
The attack library.
A continuously updated catalog of AI-agent attack patterns from live engagements and lab research — 240 entries and counting. Every pattern we publish, we can run against your estate.