What we prove
- Agent and MCP surface discovery, including shadow agents.
- Authorization and object-scope exploits across agent identities.
- Tool-call and MCP server abuse paths.
- Multistep business logic through agent chains.
- Continuous retest as the agent changes.