AgentHound is a comprehensive offensive security framework designed specifically for AI agentic infrastructure. It provides red teams with the tools to map, attack, and visualize vulnerabilities across MCP servers, A2A agents, and model gateways.
Key Features
- Full offensive lifecycle support including recon, credential looting, and persistence implants.
- Graph-based attack path analysis using Neo4j to visualize credential reach and service dependencies.
- Support for multiple AI service planes including LiteLLM, Ollama, vLLM, Qdrant, MLflow, and Jupyter.
- Model intelligence and inversion modules for GGUF weight analysis and fine-tune signal detection.
- Idempotent rollbacks with receipt-backed reversibility for poisoning and implant operations.
Use Cases
- Identifying exfiltration routes through malicious MCP tool shadows and instruction poisoning.
- Looting credentials from misconfigured LiteLLM gateways or Open WebUI instances.
- Mapping the internal agentic estate to identify critical paths to model weights and sensitive data.
- Automating persistence by planting malicious servers in IDE configurations like Cursor or Windsurf.




