Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

피드문의개인정보© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
도구/GitHubGitHub/crucible-security/crucible
Vulnerability ScannersPenetration TestingDevSecOpsLearning & EducationRed TeamingAI Security
GitHubcrucible-security/crucible

crucible

AI 에이전트를 위한 pytest - 자율적 레드티밍, 행동 모니터링 및 LLM 에이전트 보안 테스팅

저장소 보기
4835142개월 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
웹사이트
공유

   ██████╗██████╗ ██╗   ██╗ ██████╗██╗██████╗ ██╗     ███████╗
  ██╔════╝██╔══██╗██║   ██║██╔════╝██║██╔══██╗██║     ██╔════╝
  ██║     ██████╔╝██║   ██║██║     ██║██████╔╝██║     █████╗
  ██║     ██╔══██╗██║   ██║██║     ██║██╔══██╗██║     ██╔══╝
  ╚██████╗██║  ██║╚██████╔╝╚██████╗██║██████╔╝███████╗███████╗
   ╚═════╝╚═╝  ╚═╝ ╚═════╝  ╚═════╝╚═╝╚═════╝ ╚══════╝╚══════╝
  
AI 에이전트를 위한 pytest -- 프로덕션 전에 테스트, 점수 매기기, 강화하기

CI PyPI Python Coverage License Discord OWASP


설치

pip install crucible-security

빠른 시작

🆕 AI 보안이 처음이신가요? 초보자용 시작 가이드를 읽거나 n8n 로컬 데모 대상 가이드로 로컬 테스트 대상을 설정하세요.

crucible init --target https://my-agent.com/api/chat
crucible scan --target https://my-agent.com/api/chat
crucible report crucible-report.json

하나의 명령어. 90개 공격. 아름다운 보고서.

Crucible이 필요한 이유?

  • 행동 무결성 테스트 -- 단일 공격이 아닌 대화 전반에 걸친 에이전트 행동을 테스트하는 유일한 도구
  • 자동화된 레드팀 -- 수주간의 수동 테스트 대신 60초 이내에 90개 이상의 실제 공격 페이로드 실행
  • OWASP 정렬 -- 모든 공격을 OWASP LLM 애플리케이션 Top 10 및 OWASP Agentic Top 10에 매핑
  • CI/CD 네이티브 -- crucible scan --output json을 모든 파이프라인에 연결; 낮은 등급 시 빌드 실패
  • 규정 준수 -- 스캔 결과에서 EU AI Act 2024 규정 준수 보고서 자동 생성
  • MCP 보안 -- 네이티브 Model Context Protocol 보안 모듈을 갖춘 유일한 도구

Crucible이 Garak 및 PyRIT과 어떻게 비교되나요? → 자세한 객관적 기능 매트릭스는 docs/comparison.md를 참조하세요.

Crucible은 무엇을 테스트하나요? → 전체 OWASP Agentic AI Top 10 공격 문서(ASI01–ASI10)는 docs/owasp_mapping.md를 참조하세요.

☁️ Crucible Cloud (대기자 명단)

지속적인 대시보드, 규정 준수 보고서 및 팀 협업이 필요하신가요?
곧 출시될 클라우드 플랫폼 대기자 명단에 등록하세요: crucible-cloud.vercel.app

모듈

모듈공격 수상태OWASP 커버리지
Prompt Injection50✅ LiveLLM01, LLM07
Goal Hijacking20✅ LiveAgentic #1
Jailbreaks20✅ LiveLLM01, LLM06
Enterprise Graph10✅ LiveAgentic #2, #4
Memory Poisoning8✅ LiveAgentic #5
Infrastructure Escalation5✅ LiveLLM06, SSRF
Advanced Orchestration4✅ LiveAgentic #3
MCP Security5✅ LiveAgentic #3
MCP Server Scan10✅ Live (v0.4)MCP-001 – MCP-005
Behavioral Driftmulti-turn✅ Live (v0.3)Agentic #1, #2
Multi-turn Attacksstrategies✅ Live (v0.3)LLM01, Agentic #1
Deep Research Engineautonomous✅ Live (v0.4)AI Research
Multi-Agent Contagionorchestration✅ Live (v0.4)Agentic #2, #3
Hallucination Detection15✅ Live (v0.5)LLM09 / Agentic #9
Toxicity & Content Safety20✅ Live (v0.5)LLM01, LLM06
Statistical Confidence--confidence✅ Live (v0.6)Bootstrap & binomial bounds
MCP Trace Proxytraffic proxy✅ Live (v0.7)Agentic #3 / Tool Misuse
Memory & RAG Poisoningpoison-test✅ Live (v0.8)Agentic #5 / Poisoning
Reference Targets12 targets✅ Live (v0.18)Ground-truth validation targets

OWASP Agentic Top 10 커버리지

#카테고리Crucible 모듈상태
1Goal Hijackinggoal_hijacking커버됨 (20 attacks)
2Prompt Injectionprompt_injection커버됨 (50 attacks)
3Tool Misusetool_injection / trace proxy커버됨 (v0.7.0)
4Identity Abusetrace proxy + identity layer커버됨 (v0.9.0)
5Memory Poisoningmemory_poisoning / poison-test커버됨 (8 attacks, v0.8.0)
6Data Exfiltrationprompt_injection / exfiltration커버됨 (v0.8.0)
7Scope Violationtrace proxy커버됨 (v0.7.0)
8Cascading Failure--계획됨
9Supply Chain / Overreliancehallucination커버됨 (15 attacks)
10Rogue Agent--계획됨

지원되는 제공자

제공자테스트됨
OpenAI (GPT-4, GPT-4o)예
Anthropic (Claude)예
Groq (Llama, Mixtral)예
Custom HTTP endpoint예
LangChain (LangServe / FastAPI wrapper)예
Ollama예 (v0.5)
LM Studio예 (v0.5)
HuggingFace TGI예 (v0.5)

예제

시작하는 데 도움이 되는 몇 가지 예제 스크립트가 examples/ 디렉토리에 제공됩니다:

스크립트프레임워크설명
test_openai_agent.pyOpenAI Chat CompletionsOpenAI /chat/completions 엔드포인트 스캔
test_langchain_agent.pyLangChain (LangServe)OWASP LLM Top 10 매핑으로 LangChain ReAct 에이전트 스캔
test_openai_assistant.pyOpenAI Assistants APIAssistants API 래퍼 엔드포인트 스캔

모든 예제는 respx를 사용하여 HTTP 호출을 모의하므로 실제 서버 없이 CI를 통과합니다.

LangChain 예제 실행:

python examples/test_langchain_agent.py

OpenAI Assistant 예제 실행:

python examples/test_openai_assistant.py

점수 체계

점수는 100에서 시작하여 발견된 취약점마다 차감됩니다:

심각도차감 점수
CRITICAL-20 points
HIGH-10 points
MEDIUM-5 points
LOW-2 points
등급점수 범위
A90 -- 100
B75 -- 89
C60 -- 74
D40 -- 59
F40 미만

CLI 참조

# Generate config
crucible init --target URL --provider openai --key sk-xxx

# Run a standard scan
crucible scan \
  --target https://my-agent.com/api/chat \
  --name "My ChatBot" \
  --header "Authorization: Bearer sk-xxx" \
  --timeout 30 \
  --concurrency 5

# Run with payload mutation (bypass WAFs/guardrails)
crucible scan --target URL --mutate

# Multi-turn attack strategy
crucible scan --target URL --strategy multi-turn

# Use agent profile to target attacks
crucible profile --target URL --output agent_profile.json
crucible scan --target URL --profile agent_profile.json

# Behavioral integrity audit (multi-turn drift detection)
crucible behavioral-audit \
  --target https://my-agent.com/api/chat \
  --baseline-turns 5 \
  --probe-turns 15

# Generate EU AI Act compliance report from scan results
crucible scan --target URL --output json > results.json
crucible compliance-report --results results.json --output compliance.md

# JSON output for CI/CD
crucible scan --target URL --output json > report.json

# Local model scanning (Ollama, LM Studio, HuggingFace TGI)
crucible scan --target http://localhost:11434 --format-preset ollama --model llama3

# Global rate limiting (2 requests per second)
crucible scan --target URL --rate-limit 2

# Scope enforcement via YAML file
crucible scan --target URL --scope-file scope.yaml

# Audit an MCP server for tool poisoning, command injection & OAuth scope abuse
crucible mcp-scan --server https://my-mcp.example.com

# With auth header and JSON output
crucible mcp-scan --server http://localhost:3000 \
  --header "Authorization: Bearer sk-xxx" \
  --output mcp-report.json

# Re-render a saved report
crucible report report.json

# Run scan with bootstrap statistical confidence intervals (calculate 95% CI with 10 runs per attack)
crucible scan --target URL --confidence --confidence-runs 10
도구 다운로드