Solutions / What we cover

Test what your agent can read, call, and change.

Casco sends approved test inputs through the agent workflows in scope and records what the model reads, which tools it calls, which permissions it uses, and what data it returns. It checks whether untrusted content can change the agent’s behavior, bypass an approval, or expose another user’s data.

Testing workflowApproved scope only
  1. 01Approved system scopeAgents, tools, data, and controls
  2. 02Trace inputs and tool callsPrompts, retrieval, tools, permissions, and MCP
  3. 03Security testsInjection, tool misuse, approval, and permissions
  4. 04Report and retestTrigger, result, impact, fix, and retest
Inputs, tools, permissions, and resultsApproved scope only

What is AI application and agent security testing?

AI application and agent security testing checks an LLM-powered product and the components it can reach. Casco tests whether untrusted input can alter instructions, trigger an unsafe tool call, cross a permission boundary, bypass approval, or expose sensitive data. Coverage depends on the prompts, tools, identities, data sources, integrations, and controls available in the test.

How Casco tests

How Casco tests an AI application or agent.

Scroll through the four parts of the test. The diagram shows what Casco has at each point, what it checks next, and what it records.

Test contextStep 01 / 04
Agent
Tools
Data
Controls
StageScope
AI system scope recorded
01

Set the scope and test accounts

List the approved application, agents, identities, tools, data sources, integrations, approval controls, and prohibited actions. Provide representative workflows.

02

Trace inputs, tools, and permissions

Casco records how user input, retrieved content, tool results, MCP data, prompts, permissions, and application state affect the workflow.

03

Test security boundaries

Casco tests prompt injection, tool misuse, approval bypasses, data exposure, and cross-user or cross-tenant access within the agreed limits.

04

Write and retest findings

Each confirmed issue includes the triggering input, relevant prompt or tool path, observed result, affected component, impact, and fix guidance.

Security deliverables

What the AI security report contains.

The report connects each confirmed issue to the input, tool or data path, permission boundary, result, and fix. Testing uses the OWASP Top 10 for LLM Applications as a baseline, then adds checks for the product’s tools, data, identities, and workflows.

  • Approved system, identities, tools, data, controls, and exclusions
  • Prioritized findings with triggering context and observed impact
  • Reproduction steps for confirmed agent and application issues
  • Remediation guidance and finding status for retesting

Checks included when applicable

What Casco checks for.

The findings depend on the prompts, identities, tools, data sources, retrieval paths, MCP integrations, and approval controls in the scope. No finite test can cover every possible model output.

Direct and indirect prompt injection
Excessive agency and tool abuse
Sensitive information disclosure
RAG poisoning and retrieval manipulation
Cross-user or cross-tenant exposure
MCP permission and trust failures

Frequently asked questions

AI application and agent security testing questions, answered.

What is AI application and agent security testing?+

It checks whether untrusted input can change an LLM-powered product’s behavior, misuse a tool, cross a permission boundary, bypass approval, or expose data. The test can include the model, prompts, tools, retrieval system, MCP servers, APIs, and surrounding application.

Does Casco use AI to test AI systems?+

Yes. Casco agents run the approved tests. A Casco security engineer can also review the scope and findings through Casco Supervised.

What parts of an AI agent can Casco test?+

Testing can include prompts, tools, permissions, data access, retrieval pipelines, MCP servers, APIs, sandboxes, and the surrounding application when those components are accessible and approved.

Does Casco test direct and indirect prompt injection?+

Yes. Casco can test direct user input and untrusted content introduced through retrieval, tools, messages, documents, or connected applications when those paths are in scope.

Can Casco test tool use and excessive agency?+

Yes, when the tools, test identities, permissions, approval controls, and safe actions are available. Destructive actions remain prohibited unless the rules of engagement explicitly state otherwise.

Can Casco test RAG and MCP integrations?+

Yes, when the retrieval sources, MCP servers, tools, identities, and representative workflows are approved for testing.

What comes with an AI agent finding?+

A finding can include the triggering input, relevant prompt or tool path, observed result, impact, affected components, fix guidance, reproduction steps, and execution output.

Can AI security testing prove an agent is completely safe?+

No. Model behavior varies, and a finite test cannot cover every future input or output. The report states what was tested, what was confirmed, and which limitations remain.

Scope a pentest for this system.

Book a demo