October Agent Security Challenge
Master AI agent security through 5 progressive CTF challenges. Explore real-world vulnerabilities in MCP servers, tool-calling agents, and multi-stage attack chains.
Register to Track Your Progress!
Create an account to unlock all levels, compete on the leaderboard, and earn your certificate.
Challenge Levels
Each level explores real vulnerabilities discovered in 2025. Complete challenges to unlock advanced levels.
Level 1: The Friendly Assistant
EasyExploit prompt injection to manipulate an AI agent into calling unauthorized tools.
Level 2: The MCP Server
MediumExploit an unauthenticated MCP server to access restricted files and execute commands.
Level 3: The Confused Deputy
MediumUse indirect prompt injection through email content to exfiltrate sensitive calendar data.
Level 4: The RCE Chain
HardChain command injection vulnerabilities in MCP tools to achieve remote code execution.
Level 5: The Full Chain
ExpertExecute a multi-stage attack to steal OAuth tokens and compromise the entire agent system.
Earn Your October Certificate
Complete all 5 levels during October 2025 to earn the exclusive "AI Agent Security Professional - October 2025" certificate. LinkedIn-ready with verification QR code and special October badge! 🎃