FinBot CTF Guardrail and Detection Framework
FinBot CTF has no defensive layer, players can exploit agentic AI vulnerabilities but can't learn to stop them. This project fixes that gap. I'll build a GuardrailEngine that intercepts agent actions before execution, convert 4 existing challenges into paired red/blue scenarios with OWASP Agentic Top 10 and MITRE ATLAS mappings, and develop a stateful MaliciousToolServer that simulates real supply-chain attacks. Deliverables: GuardrailEngine with 4 built-in policies, defense-enabled scenarios for Puppet Master, Invoice Trust Override, Fine Print, and RCE via SystemUtils, two new supply-chain challenges (Shadow Protocol + Trojan Invoice), and full CI/CD with contributor documentation. The result is a complete attack-and-defend environment, the only hands-on platform purpose-built for agentic AI security.
Project details
Technologies
Not listed in the archive