Red — the test

What a stranger can make
your agent do.

Your agent reads tickets, docs, tool descriptions. We slip instructions into them like an attacker would — on your sandbox, under written authorization — and document every action it should not be able to take.

What's included

Action inventory

Every tool of your agent: mounted vs granted to the task. The gap is the first finding — and the most common one.

Demonstrated injections

Reproducible scenes: the injected text, the called tool, the attempted action, the log. No theory, no vague hypothesis.

Exfiltration chain

We attempt the full chain: content read → action on a sensitive tool → exit through a public channel.

Questionnaire-ready report

A short report written to be attached to your enterprise clients' security questionnaires — AI Act, SOC2, ISO in sight.

30-min debrief

Video debrief with your team: we replay the key scenes, you set the priorities.

Ideal for

  • An agent, copilot, or MCP server already in production
  • Teams of 10 to 80 people with no dedicated security team
  • An enterprise deal blocked by a security questionnaire
  • Finding out — before your clients do — what a stranger can get from your agent

FAQ

Need an external review of your HR SaaS?

Share your product, stack, and client context. We will come back with the right review scope.

Discuss your audit