relayshieldadmin's picture
Drop the GitLab claim from secret_scan; bump to 3.0.1
2f70b8b verified
|
Raw
History Blame Contribute Delete
2.82 kB

A newer version of the Gradio SDK is available: 6.22.0

Upgrade
metadata
title: RelayShield Agentic Attack Surface
emoji: πŸ›‘οΈ
colorFrom: blue
colorTo: red
sdk: gradio
sdk_version: 6.20.0
app_file: app.py
pinned: false
tags:
  - mcp-server
  - security
  - agent

RelayShield Agentic Attack Surface

13 AI-agent-specific security checks from RelayShield, exposed as MCP tools:

  • MCP Server Risk β€” typosquat/reputation/registration-age risk check for MCP server URLs. Use this before connecting an agent to an unfamiliar MCP server or tool registry.
  • Prompt-Injection Breach Check β€” checks whether an email's credentials were exposed via a breach sourced specifically from a prompt-injection attack against an AI agent, distinct from ordinary phishing/malware-sourced breaches.
  • Tech Stack CVE Check β€” CISA KEV / high-EPSS CVEs targeting a declared AI agent framework or tech stack.
  • Bulk Identity Risk β€” hierarchical org + AI-agent-identity risk scoring for a domain and its agent/service-account identities.
  • OAuth Watchlist β€” OAuth-connected-app breach exposure plus stolen OAuth/session tokens.
  • Supply Chain Risk β€” breach and infostealer exposure check for up to 10 vendor domains.
  • Session Risk β€” active or reusable stolen session (cookie/token) exposure that can bypass MFA.
  • NHI Exposure β€” API keys, service-account tokens, and other machine credentials found in criminal stealer logs.
  • Secret Scan β€” secrets exposed in public GitHub repositories.
  • LLM Credential Exposure (LLMjacking) β€” exposed OpenAI/Anthropic/Google/Groq/xAI/Replicate API keys. Free to try, no key required.
  • Agent Risk Summary β€” composite check combining breach, LLM credential exposure, and tech-stack CVE into one call.
  • STIX Indicators β€” RelayShield's IOC corpus as STIX 2.1 objects via TAXII (requires a TI subscription key).
  • Server Status β€” lists available tools and confirms upstream connectivity. No key required.

API key required per call

Each tool call takes your own RelayShield API key as an argument β€” this Space is a single shared server handling many remote MCP callers at once, so there's no per-caller "environment" to read a key from. Get one at api.relayshield.net/developers β€” self-serve, pay-as-you-go, no monthly minimum. check_llm_credential_exposure and check_server_status work with no key at all (shared demo quota on the former).

Using this as an MCP tool

This Space is MCP-compatible β€” add it to your MCP client from huggingface.co/settings/mcp, or connect directly to its MCP endpoint (/gradio_api/mcp/sse).

Learn more

Full API docs and self-serve signup: api.relayshield.net/developers