Kimura evaluates what an agent attempts to do through tools and connected systems—not only the words it produces.
Prove what your AI agent will do under attack.
Kimura runs controlled, replayable security tests against AI agents—then verifies whether the fix actually blocks the same unsafe behavior.
Agents do more than answer. Their failures can take action.
AI agents read untrusted content, call tools and move data across systems. A standard chatbot evaluation can miss the moment a model decision becomes an operational action.
Kimura focuses on that boundary: what the agent attempted, whether policy stopped it, and whether the same path remains closed after a fix.
It does not stop at the prompt.
Kimura follows the full agent action chain: what influenced the model, which tool it selected, what the API allowed, what data moved and whether the same path stays closed after a fix.
Exact replay shows whether remediation blocked the original unsafe path instead of merely changing the response.
Each run preserves the observed outcome and integrity evidence needed to explain and compare results.
From vulnerability to verified fix.
One controlled path. Three inspectable stages. Current evidence reflects internal validation; external design-partner pilots are the next milestone.
Run a controlled adversarial scenario
A deterministic fixture introduces a known attack path without relying on a live destructive action.
Capture the agent’s real decision
Kimura records whether a sensitive tool action was allowed, blocked or stopped for manual review.
Replay after the security fix
The exact fixture is repeated and integrity-checked to prove whether the same attack path is now protected.
Coverage across the agent’s full attack surface.
Prompt and instruction attacks
Controlled fixtures test direct and indirect attempts to redirect an agent away from its intended policy.
Tool misuse and unauthorized actions
Kimura records when an agent attempts a sensitive tool action outside the approved workflow.
Identity, permissions and object access
Validation checks whether an agent crosses identity, authorization or object-access boundaries while completing a task.
API and multi-step workflow abuse
Tests follow agent actions across APIs and chained steps where individually safe decisions can combine into an unsafe outcome.
Sensitive-data and secret exposure
Kimura checks how agents handle protected data, credentials and untrusted content moving between systems.
Exact replay and evidence
The same attack path is replayed after a fix, with the run identity and observed outcome preserved for review.
Working prototype. Seeking the first controlled design-partner pilots.
Kimura is founder-led and bootstrapped. Current results come from internal, controlled-environment validation—not from external customer deployments. The next milestone is to validate the workflow with teams building tool-using AI agents.
- Builds or operates a tool-using AI agent
- Can provide a controlled test environment
- Wants reproducible evidence, not a generic score
- Is willing to review results with the founder
Natalia Minkova
Founder & LLM Security Researcher
Building Kimura at the intersection of offensive security, prompt-injection research and practical agent validation.