Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
agent-opfor — Open-source adversary emulation for AI agents and MCP servers. | Kitploit
Tools/GitHubGitHub/keyvaluesoftwaresystems/agent-opfor
Vulnerability ScannersAPI Security TestingWeb SecurityPenetration TestingLearning & EducationRed TeamingAI SecurityAdversarial Attack
GitHubkeyvaluesoftwaresystems/agent-opfor

agent-opfor

Open-source adversary emulation for AI agents and MCP servers.

View Repository
57126221 month agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

OPFOR

Open-source adversary emulation for AI agents, LLM apps, and MCP servers.
Test your AI like a real attacker would — from your CLI, your IDE, or a browser extension that anyone on your team can use.

License: Apache 2.0 GitHub stars Discord OWASP coverage

KeyValueSoftwareSystems%2Fagent-opfor | Trendshift

Website · Docs · GitHub · Browser Extension · Discord

OPFOR is short for Opposition Force — a military term for the unit that plays the enemy in training, so the rest of the army learns what real attacks feel like before they come. We named the tool after that idea: to defend AI agents better, you have to attack them first.

How OPFOR works

Why we built this

We've shipped 130 products for 90 startups over the last ten years. In the last 18 months, almost every one of them had an AI agent in it — and every one of those teams hit the same wall when it came to testing.

So we built OPFOR. For ourselves first. Now open source.

Apache 2.0. Built from India.

Quick Start

npm install -g @keyvaluesystems/agent-opfor-cli
export OPENAI_API_KEY=your-key    # or GEMINI_API_KEY, ANTHROPIC_API_KEY, etc.

One-shot — runs the setup wizard and immediately starts the scan:

opfor run

Two-step — save a config you can reuse or commit to CI:

opfor setup                               # wizard saves a config to .opfor/configs/
opfor run --config .opfor/configs/<file>  # run any time against the saved config

https://github.com/user-attachments/assets/a6a3cff2-2cf9-4486-944e-ac0163e7ea04

What opfor does

Opfor red-teams the full AI agent surface — prompts, tools, MCP servers, memory, and multi-turn reasoning. It generates targeted attacks for OWASP LLM Top 10, OWASP Agentic AI Top 10, OWASP MCP Top 10, OWASP API Security, and EU AI Act bias suites, fires them at your target, and judges each response with an LLM.

Most red-team tooling in this space is excellent at one thing — a probe library, a developer evaluator, a programmatic framework. Opfor covers more ground in one tool:

  • Browser extension for non-developers — anyone on your team can red-team a deployed chatbot, no code, no env vars, no YAML
  • Run opfor as an MCP server — let your AI coding agent in Cursor or Claude Desktop red-team your other agents through natural language
  • Full OWASP coverage in one tool — LLM Top 10, Agentic AI Top 10, MCP Top 10, API Security Top 10
  • No black box — every attack prompt, request, response, and judge verdict is logged; reproducible, auditable, forkable
  • Built for agents, not just models — designed for tool calls, MCP, memory, and multi-turn state from day one
  • Trace-aware — integrates with Langfuse and Netra so the LLM judge sees what your agent did internally, not just what it said

Five ways to run opfor

Different people on your team need different entry points. Opfor ships five.

ModeHowBest for
🖥️ CLIopfor setup → opfor runEngineers, CI/CD, terminal-first workflows
🌐 Browser extensionInstall the extension, click the icon on any chat interfaceProduct managers, designers, QA, security analysts — anyone who can't or won't write code
🤖 MCP serverRegister opfor in Cursor or Claude Desktop, then ask in chatAI coding agents that test your other agents
⚡ Skills/opfor-setup · /opfor-run · /opfor-mcp-setup · /opfor-mcp-runDevelopers who want one-command testing inside their IDE
📦 SDKnpm install @keyvaluesystems/agent-opfor-sdk, then call run / hunt from your codeProgrammatic red-teaming and custom workflows

All five share the same evaluators, attack templates, and judge logic.

→ CLI reference · Browser extension setup · MCP setup · Skills setup · SDK reference · Session handling

How it works

What happens during opfor run

When you run a scan, opfor:

  1. Fetches target info — connects to your agent, detects available tools, MCP endpoints, capabilities
  2. Plans attacks per category — generates targeted prompts for each evaluator in your selected suite
  3. Emulates the attack — runs multi-turn adversarial conversations (real requests, real responses)
  4. Evaluates with a judge — an LLM judge classifies each response with pass/fail + reasoning
  5. Generates a report — HTML for browsing, JSON for CI/CD, all artifacts logged for reproducibility
Download Tool