ZeroLeaks Launches Automated Red Teaming Platform for AI Agents
Key Takeaways
- ▸ZeroLeaks automates adversarial testing of AI agents using a red team of specialized AI agents, informed by thousands of real-world exploits rather than synthetic checklists
- ▸The platform tests across prompts, tool calls, MCP servers, RAG pipelines, and extended multi-turn conversations—covering the full attack surface of modern AI applications
- ▸Integrates with CI/CD pipelines to scan every pull request that changes agent behavior, preventing vulnerable code from reaching production
Summary
ZeroLeaks, a new security platform built by the team behind a 100k+ star open-source repository of documented prompt leaks and jailbreaks, launches automated red teaming capabilities for AI agents, endpoints, and MCP tools. The platform uses specialized AI agents to continuously test for prompt injection, data leakage, unsafe actions, and other vulnerabilities in production AI systems, catching risks before they reach users. ZeroLeaks offers both on-demand scanning for security teams and automated CI/CD integration that gates merges on security findings. Every vulnerability discovered includes reproducible evidence, guided remediation steps, and validation mechanisms to confirm fixes, with findings ranked by severity and exportable for compliance reporting.
- Commercial tiers (Team at $99/seat/month, Business at $999/month) offer unlimited scans, automated validation, GitHub merge gates, PDF export, and API access; Enterprise includes self-hosting and dedicated support
- Grounded in open-source research on real vulnerabilities, not synthetic tests, making remediation guidance more relevant to actual production risks
Editorial Opinion
ZeroLeaks addresses a critical gap in AI safety: the lack of scalable, automated testing for production AI agents. Using AI agents to red-team other AI agents is appropriately meta, and the platform's grounding in real documented exploits (rather than theoretical attack vectors) makes it a pragmatic tool for teams shipping AI products. The unlimited-scanning model removes perverse incentives to skip security testing due to quota limits—a refreshing approach in a market often built on usage-based pricing. This suggests the AI security market is maturing beyond point solutions toward comprehensive, developer-first defensive infrastructure.


