Erratum (v1.1, 2026-07-10): This version corrects a CVE misattribution present in v1.0. CVE-2026-25253 was cited as an example of MCP tool poisoning / supply-chain marketplace contamination; per the NVD it is actually an unrelated OpenClaw WebSocket auto-connect vulnerability, and is not associated with the tool-poisoning or "135,000 instances" claims made in v1.0. The tool-poisoning discussion is re-anchored to the Invariant Labs "Tool Poisoning Attacks" research (2025). See the attached ERRATUM-2026-07-10.md file; no other claims are affected. The proliferation of autonomous AI agents has exposed critical security gaps, from tool poisoning to supply chain attacks, such as MCP tool-description poisoning (Invariant Labs, Tool Poisoning Attacks, 2025). This paper traces the evolution of the Agent Security Harness, an open-source adversarial testing framework, from its initial 209 tests to a community-enhanced suite of 342 tests, culminating in a perfect 10/10 evaluation score. We detail the challenges of integrating community plugins, which initially dropped the score to 6.5/10, and the subsequent recovery through manifest-based integrity checks, trust tiers, and hardening protocols. Building on our prior work in Decision Load Index (DLI) and Constitutional Self-Governance (CSG), we propose a sustainable model for open contributions, including bounties and good-first issues. The framework's journey demonstrates how collaborative red-teaming can mitigate agent risks, aligning with AIUC-1 standards and offering a blueprint for enterprise-grade security. We outline the v4.0 roadmap and invite further participation to foster a robust, collective defense against emerging threats.
Michael K. Saleme (Fri,) studied this question.