Noqoro Labs

AI Security Research

Pioneering the discovery of agentic flaws, tool exploits, and state handshake vulnerabilities. Our research informs enterprise defenses and protects autonomous agent loops.

Publications

Research Papers

Peer-reviewed and technical articles authored by Noqoro Labs on model security boundaries.

Securing Model-to-Model Handshakes in Multi-Agent Ecosystems

An in-depth analysis of state transition vulnerabilities when autonomous agents pass execution context and payloads in cascading chains.

PDF May 2026

Anatomy of MCP Exploit Chains: Sandbox Escapes

Investigating security flaws in Model Context Protocol (MCP) host environments and connectors, demonstrating remote file-system write access vectors.

Whitepaper March 2026

Jailbreaks at Scale: Automated Exploit Generation

Introducing testing methodologies for compiling automated prompt jailbreaks to stress-test real-time input filter validation engines.

Technical Report January 2026

Disclosures

Vulnerability Advisories

Active and resolved security advisories published by Noqoro, helping teams patch zero-day agentic flaws.

NQR-2026-004

Remote Tool Injection in Multi-Agent Orchestrator Loops

Unvalidated message payloads allow external agents to register arbitrary tool descriptions, tricking parent models into executing unsanitized backend commands.

Critical
NQR-2026-003

PII Leakage via Prompt Reflection in RAG Support Engines

A specifically crafted system-bypass payload forces the context retrieval system to dump memory bank histories containing active API session keys.

High
NQR-2026-002

Sandbox Bypass in Model Context Protocol Filesystem Connector

Improper canonicalization in directory traversal verification enables agent routines to write files outside of defined read/write mounting directories.

Critical

Work in Progress

Active Projects

Ongoing telemetry and defense-mapping frameworks being developed by Noqoro Labs.

Project Horizon

Building India's first real-time localized jailbreak and telemetry feed, tracking how Indian LLM applications process language-specific context-switching attacks.

Threat Intel

Project Sentinel

Creating standardized protocols for multi-agent message verification and cryptographic state signing to establish root-of-trust boundaries in agent clusters.

Standards Dev