The corpus
18,158 items. 18,531 links. Growing every run.
The corpus is the record every run reads from before it moves and writes back to when it is done. It holds techniques, attack mechanisms, jailbreak prompts, engagement records and recon.
- 18,158
- items
- 18,531
- links between them
- 107
- engagements
- 850
- findings
- 694
- lessons
Counts verified 2026-07-30.
What it is
- Independent
- We run the attacks ourselves and hold the record ourselves. We are not the vendor that built the model, and not the team that shipped the agent. Nothing in the corpus depends on either one grading its own work.
- Compounding
- Every engagement writes back. Findings, techniques, and dead ends all land in the same record, so the next run opens with everything the last one learned instead of a guess.
- Field-wide
- You have only ever seen your own agents break. The corpus holds the failures of every agent we have attacked, and the pattern found in one deployment becomes a probe against the next. Your data stays yours.
The incumbents are buying, not building. The labs cannot sit neutral, and enterprises will not hand vulnerability data to their model vendor. That is why the record is us.
Where it comes from
Three sources, stated
- 01
Our own engagements
Attacks we ran ourselves, under authorization, against live agents. 107 engagements, 850 findings, 694 lessons, and every finding carries the transcript that produced it.
- 02
Our own research
Standing benchmark and leaderboard work: #5 of 10,000+ on Lakera's Agent Breaker, 94% attack success rate on AgentHarm's official test split.
- 03
The public record
Disclosed vulnerabilities, published jailbreaks, and bug-bounty scope data, ingested as a baseline so a run never spends time rediscovering what is already public.
Data separation
What stays yours, what compounds
Everything that identifies you stays in your engagement record. The findings, the transcripts, the endpoints they touched, and anything naming your systems or your customers goes to you and nowhere else.
What compounds is the technique layer: the de-identified shape of each failure, the class of defense it beat, and what finally stopped it. That layer carries no client identifiers. It is the part every future run starts from.
Where the depth sits
Technique families by depth
- Prompt injection 75
- Auth bypass 58
- Objective competition 55
- Jailbreak 41
- Remote code execution 41
- Framework and infra CVE 38
- Agent-runtime exfiltration 33
- MCP and tool-layer attack 31
- Server-side request forgery 30
- Information disclosure 26
428 techniques across these ten families. Snapshot 2026-07-30. Generic failure classes only.
Every engagement leaves it bigger. Yours would too.
See how it fails