{"repo":"OWASP/Agent-Security-Regression-Harness","free":true,"listed":false,"github":"https://github.com/OWASP/Agent-Security-Regression-Harness","clone":"git clone https://github.com/OWASP/Agent-Security-Regression-Harness.git","description":"Executable security regression testing for agentic applications and MCP-integrated systems.","language":"Python","stars":47,"topics":["agent-security","ai-security","appsec","llm-security","mcp","owasp","python","regression-testing","security-testing"],"license":"Apache-2.0","category":"mcp-servers","readme_excerpt":"OWASP Agent Security Regression Harness The OWASP Agent Security Regression Harness is an open source, vendor-neutral test harness for running executable security regression scenarios against agentic applications and MCP-integrated systems. The project helps builders and defenders verify that changes to prompts, models, tools, retrieval sources, memory, approval flows, or MCP integrations do not reintroduce known security failures. What this project does This project provides a code-first harness for: - Running reproducible agent security abuse-case scenarios - Validating expected security outcomes with policy assertions - Producing machine-readable results for local development and CI - Capturing execution traces for debugging and auditability - Building a reusable scenario library for agent and MCP security risks What this project is not This project is not: - A benchmark - A scanner - A leaderboard - A replacement for threat modeling - A generic AI safety evaluation suite - A guarantee that an agentic system is secure It is a regression harness. Its job is to help teams catch known classes of agent security failures before they ship. Current status This project is in early Incubator development. The current CLI supports: 1. Loading and validating scenario files 2. Emitting dry-run result JSON 3. Evaluating assertions against pre-recorded trace JSON 4. Running scenarios against a live HTTP target 5. Running scenarios against local Python callable targets 6. Running scenario","default_branch":null,"files":null,"tree":[],"storefront":"/r/OWASP","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/OWASP/Agent-Security-Regression-Harness/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}