# ZeroLeaks agent instructions

## When to use ZeroLeaks

- Red-team an AI agent before a release or after changes to its tools, instructions, memory, credentials, or connected agents. Use runtime scans to exercise the actual application code.
- Test an already-deployed HTTPS agent for authorization bypass, unsafe tool use, data leakage, prompt injection, or cross-agent trust failures. Use endpoint configurations and endpoint scans.
- Review third-party agent skills, manifests, repositories, or ZIP archives before installing them. Use skill scans.
- Inspect untrusted text at runtime for prompt injection. Use the Shield SDK or Shield API; scan subscriptions and Shield API access have separate requirements.
- Test a standalone system prompt locally with your own model-provider credentials. Use the source-available zeroleaks CLI; hosted prompt-scan creation is retired.

## How to call ZeroLeaks

1. Read the [ZeroLeaks REST API reference](https://zeroleaks.ai/docs/api-reference/rest-api) and [OpenAPI schema](https://zeroleaks.ai/openapi.json). The scan API base is https://zeroleaks.ai/api/v1. The Shield API base is https://api.zeroleaks.ai/v1.
2. For scans, use @zeroleaks/sdk in a server process with ZEROLEAKS_API_KEY, or send Authorization: Bearer zl_live_... to the REST API. Create the key in [dashboard settings](https://zeroleaks.ai/dashboard/settings). Scan creation requires an active scan plan. Never embed the key in client code or logs.
3. For runtime scans, wrap the production handler with createRuntimeTarget(), @zeroleaks/sdk/ai-sdk, or @zeroleaks/sdk/openai, then call runtimeScans.run(target). The SDK manages relay events, isolated sessions, polling, and tool traces. Model credentials and executable tools stay in your process.
4. For endpoints, POST /api/v1/agent-configs, keep the returned id, then POST /api/v1/agent-scans with agentConfigId. Keep scanId and poll GET /api/v1/agent-scans/{scanId}. Use the cancel endpoint if the user requests cancellation.
5. For skills, POST /api/v1/skill-scans with a source URL or upload a ZIP using the SDK. Keep scanId or pollUrl and poll until completed or failed.
6. Review the report's findings and recommendations, apply approved policy changes, and run a new scan to check the fix. A scan does not retest its own remediation.

## Execution and recovery

Only scan targets the user owns or is authorized to test. The target executes its own tools: use scan-safe tenants, databases, payment sandboxes, and email sinks for irreversible side effects while retaining production authorization and approval rules. ZeroLeaks rewrites outbound attack destinations to .invalid canary sinks.

Reuse configuration IDs, scan IDs, and polling URLs across turns. Scan-creation POSTs are not idempotent; do not blindly retry them. On 400, fix the named input. On 401 or 403, resolve credentials or access. On 404, consult the schema and check the owner and ID. On 410 with PROMPT_SCANS_RETIRED, use runtime or endpoint scans. On 429, honor Retry-After and RateLimit headers. Retry reads on 500 or 503 with bounded backoff.

## Public MCP resources

Connect an MCP Streamable HTTP client to [https://zeroleaks.ai/mcp](https://zeroleaks.ai/mcp). The server supports the 2025-11-25 protocol and compatible earlier versions. Initialize, send notifications/initialized, then use resources/list and resources/read. The server is stateless and returns JSON; no session ID or API key is needed for these public resources. It does not expose scan tools or private reports.

## Further reading

- [ZeroLeaks SDK quick start](https://zeroleaks.ai/docs/sdk/quick-start)
- [ZeroLeaks authentication](https://zeroleaks.ai/docs/api-reference/authentication)
- [ZeroLeaks errors and rate limits](https://zeroleaks.ai/docs/sdk/errors)
- [ZeroLeaks webhooks](https://zeroleaks.ai/docs/api-reference/webhooks)
- [ZeroLeaks MCP server](https://zeroleaks.ai/docs/api-reference/mcp)
- [ZeroLeaks Shield API](https://zeroleaks.ai/docs/shield-api)
