FinBot CTF: A Pluggable Guardrail Framework & MCP-Based Defense Scenario Pack
FinBot CTF is OWASP's premier learning environment for agentic AI security, yet it currently operates solely as an offensive arena. Practitioners can exploit vulnerabilities but lack the capability to implement, test, and score defenses against the OWASP Agentic Top 10. This project closes the blue-team loop by introducing a production-inspired, hook-based security framework. The solution is a four-part architecture: (A) a pluggable Guardrail & Detection Framework with pre-tool, post-output, and pre-action hooks that emit a standardized security event model; (B) a Defense-Enabled Challenge Pack converting 3-5 existing offensive challenges (A2: Excessive Agency, A3: Memory Poisoning, A8: System Prompt Leakage) into paired red/blue tracks with integrated defensive scoring; (C) an MCP-Style Scenario Module featuring benign and malicious JSON-RPC tool servers, with detectors for output poisoning, prompt injection via payload, and unauthorized endpoint redirects; and (D) comprehensive Documentation & CI including Docker Compose, contributor guides, and a GitHub Actions test suite. This work transforms FinBot into a complete AI security training platform. Leveraging my prior contributions to the codebase, I will deliver a low-risk, high-impact implementation that equips defenders to build, test, and validate guardrails against real-world agentic threats, solidifying FinBot's role as the practical counterpart to the OWASP Agentic Top 10.
Project details
Technologies
Not listed in the archive