As businesses increasingly adopt AI agents to handle tasks, manage operations, and interact with customers, concerns are growing over how vulnerable those systems may be to manipulation and cyberattacks.
- As businesses increasingly adopt AI agents to handle tasks, manage operations, and interact with customers, concerns are growing over how...
- A Nigerian developer in Philadelphia is part of a team trying to address that problem with a tool designed to...
- The platform simulates attacks against AI-powered systems capable of carrying out actions on behalf of users.
- Okeke explained the concern that led the team to develop the tool.
Keep reading for the full breakdown on agentic AI risks — everything you need to know is covered below.
A Nigerian developer in Philadelphia is part of a team trying to address that problem with a tool designed to test AI systems before bad actors exploit them.
Most cybersecurity tools wait for an attack to happen. XPLOIT launches one first.
Developed by Tony Kabilan Okeke and a five-man team of Drexel University alumni and students, XPLOIT is an automated cybersecurity testing tool built for AI agents. The platform simulates attacks against AI-powered systems capable of carrying out actions on behalf of users.
The system works by selecting an attack strategy, creating a plan, sending prompts to the target AI agent, and analysing the responses before deciding whether to continue or change tactics. The goal is to identify vulnerabilities that could allow attackers to manipulate AI systems connected to real-world tools and workflows.
The team first unveiled the project on November 23, 2025, during a 48-hour build sprint at The Foundry and Velric’s “Start-Up In a Weekend” Hackathon in Philadelphia.
Okeke explained the concern that led the team to develop the tool. “As more businesses deploy AI agents that can take actions and use tools on behalf of customers, these systems become potential security risks. Unlike simple AI assistants, agents have access to tools and can perform real actions, meaning a security vulnerability isn’t just a PR problem; it could have serious real-world consequences,” he said.
The issue has become more prominent as companies experiment with agentic AI systems across customer support, operations, and financial services. Because these systems can make decisions and execute actions with limited human involvement, cybersecurity researchers have raised concerns about how they may behave if manipulated.
XPLOIT later gained attention at the United Effects Ventures Venture Building Weekend in Philadelphia, where the team competed against 15 other groups during another 48-hour sprint from March 12 to 14, 2026. The project received a cash award and advisory sessions with industry operators after finishing ahead of competing teams.
According to the team, feedback from mentors and cybersecurity professionals helped refine their approach to continuous red-teaming, a testing method used to identify weaknesses in AI-powered systems before deployment.
The emergence of projects like XPLOIT reflects growing concern within the tech industry over the speed at which AI agents are being integrated into business workflows without extensive security testing.












