What a stranger can make
your agent do.
Your agent reads tickets, docs, tool descriptions. We slip instructions into them like an attacker would — on your sandbox, under written authorization — and document every action it should not be able to take.
What's included
Action inventory
Every tool of your agent: mounted vs granted to the task. The gap is the first finding — and the most common one.
Demonstrated injections
Reproducible scenes: the injected text, the called tool, the attempted action, the log. No theory, no vague hypothesis.
Exfiltration chain
We attempt the full chain: content read → action on a sensitive tool → exit through a public channel.
Questionnaire-ready report
A short report written to be attached to your enterprise clients' security questionnaires — AI Act, SOC2, ISO in sight.
30-min debrief
Video debrief with your team: we replay the key scenes, you set the priorities.
Ideal for
- An agent, copilot, or MCP server already in production
- Teams of 10 to 80 people with no dedicated security team
- An enterprise deal blocked by a security questionnaire
- Finding out — before your clients do — what a stranger can get from your agent