Securing Model-to-Model Handshakes in Multi-Agent Ecosystems
An in-depth analysis of state transition vulnerabilities when autonomous agents pass execution context and payloads in cascading chains.
Noqoro Labs
Pioneering the discovery of agentic flaws, tool exploits, and state handshake vulnerabilities. Our research informs enterprise defenses and protects autonomous agent loops.
Publications
Peer-reviewed and technical articles authored by Noqoro Labs on model security boundaries.
An in-depth analysis of state transition vulnerabilities when autonomous agents pass execution context and payloads in cascading chains.
Investigating security flaws in Model Context Protocol (MCP) host environments and connectors, demonstrating remote file-system write access vectors.
Introducing testing methodologies for compiling automated prompt jailbreaks to stress-test real-time input filter validation engines.
Disclosures
Active and resolved security advisories published by Noqoro, helping teams patch zero-day agentic flaws.
Unvalidated message payloads allow external agents to register arbitrary tool descriptions, tricking parent models into executing unsanitized backend commands.
A specifically crafted system-bypass payload forces the context retrieval system to dump memory bank histories containing active API session keys.
Improper canonicalization in directory traversal verification enables agent routines to write files outside of defined read/write mounting directories.
Work in Progress
Ongoing telemetry and defense-mapping frameworks being developed by Noqoro Labs.
Building India's first real-time localized jailbreak and telemetry feed, tracking how Indian LLM applications process language-specific context-switching attacks.
Creating standardized protocols for multi-agent message verification and cryptographic state signing to establish root-of-trust boundaries in agent clusters.
Annual Research
Our comprehensive study surveying AI adoption, deployment architectures, threat landscapes, and control boundaries across 500+ Indian enterprise systems.
Request Access to Report