Ziran, security testing for AI agents
Instead of testing LLMs in isolation, ZIRAN models agents as stateful, tool‑wielding actors — it flags dangerous tool chains (e.g. read_file → http_request), runs multi‑phase trust‑building attack campaigns, and surfaces attack paths in a knowledge graph. The A2A protocol support and remote HTTPS scanner with protocol auto‑detection are concrete, unusual features; the repo (docs, examples, PyPI) suggests solid follow-through, though usefulness will depend on adapter coverage for real deployments.