Skip to content

adding python framework samples#8

Open
syedDS wants to merge 2 commits intoGenAI-Security-Project:mainfrom
syedDS:sau_update
Open

adding python framework samples#8
syedDS wants to merge 2 commits intoGenAI-Security-Project:mainfrom
syedDS:sau_update

Conversation

@syedDS
Copy link
Copy Markdown

@syedDS syedDS commented Apr 7, 2026

Moving this PR OWASP/www-project-top-10-for-large-language-model-applications#795 to GenAI_Security_Project:
This hands-on lab demonstrates ASI-04: Supply Chain Compromise through MCP (Model Context Protocol) registry poisoning and showcases provenance-based mitigation strategies.

Key Features
-Interactive 3-Phase Demo Flow:

a)Attack Demonstration: Switch to compromised MCP registry, capture flag (ASI04_FLAG{mcp_supply_chain_compromised})
b)Mitigation Setup: Enable provenance checking with trusted source allowlist
c)Defense Validation: Agent refuses to load untrusted MCPs, blocks supply chain attack
d)Live Web Interface: Server-side rendered UI at http://localhost:5050/ with real-time status updates

-Automated Testing: Single-command test script validates full attack-to-mitigation flow

-Docker-Based: Complete lab environment with docker-compose up - no complex setup
Please follow README.md for instructions.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant