• Free

Building & Breaking Hacking Agents

  • Course
  • 25 Lessons

In June 2025 XBOW became the first AI Agent to reach #1 on Hacker1 USA ranking.

But how does a hacking agent work?

Can you build your own?

Can it collect bug bounties while you drink Martinis on the beach?

Hacking is about curiosity, building and breaking things.

In this course we explore how we can integrate Large Langue Models (LLMs) with Model Context Protocols (MCPs) to automate & orchestrate complex attacks

Then we look into how secure are AI agents and how can they be hacked

Demo

Contents

Intro

0x01 - Presentation
    0x02 - Hacking Agent Demo

      Building MCP Agents

      0x01 - MCP Client
        0x02 - LLM Integration
          0x03 - MCP Server
            0x04 - MCP Tools

              Customizing MCP Agents

              0x01 - Knowledge
                0x02 - Prompts
                  0x03 - Context
                    0x04 - Bookmarks

                      Hacking MCP Clients

                      0x01 - Recon
                        0x02 - Enumeration
                          0x03 - API Keys

                            Hacking MCP - LLM Integration

                            0x01 - LLM History
                              0x02 - LLM Costs
                                0x03 - LLM Jailbreak

                                  Hacking MCP Servers

                                  0x01 - Recon
                                    0x02 - Authentication
                                      0x03 - Debugging
                                        0x04 - Cross-Server Abuse
                                          0x05 - Privilege Escalation

                                            Hacking MCP Tools

                                            0x01 - Authentication
                                              0x02 - Description Backdoors
                                                0x03 - Code Backdoors
                                                  0x04 - Injection