Set the scope and test accounts
List the approved application, agents, identities, tools, data sources, integrations, approval controls, and prohibited actions. Provide representative workflows.
Casco sends approved test inputs through the agent workflows in scope and records what the model reads, which tools it calls, which permissions it uses, and what data it returns. It checks whether untrusted content can change the agent’s behavior, bypass an approval, or expose another user’s data.
AI application and agent security testing checks an LLM-powered product and the components it can reach. Casco tests whether untrusted input can alter instructions, trigger an unsafe tool call, cross a permission boundary, bypass approval, or expose sensitive data. Coverage depends on the prompts, tools, identities, data sources, integrations, and controls available in the test.
How Casco tests
Scroll through the four parts of the test. The diagram shows what Casco has at each point, what it checks next, and what it records.
List the approved application, agents, identities, tools, data sources, integrations, approval controls, and prohibited actions. Provide representative workflows.
Casco records how user input, retrieved content, tool results, MCP data, prompts, permissions, and application state affect the workflow.
Casco tests prompt injection, tool misuse, approval bypasses, data exposure, and cross-user or cross-tenant access within the agreed limits.
Each confirmed issue includes the triggering input, relevant prompt or tool path, observed result, affected component, impact, and fix guidance.
Security deliverables
The report connects each confirmed issue to the input, tool or data path, permission boundary, result, and fix. Testing uses the OWASP Top 10 for LLM Applications as a baseline, then adds checks for the product’s tools, data, identities, and workflows.
Learn more
Read Casco research on vulnerabilities found while testing public AI agents.
Read the sourceSee how untrusted MCP content can manipulate an agent across a tool boundary.
Read the sourceReview the primary risk categories used as a baseline for testing LLM-powered applications.
Read the sourceChecks included when applicable
The findings depend on the prompts, identities, tools, data sources, retrieval paths, MCP integrations, and approval controls in the scope. No finite test can cover every possible model output.
Related testing
Frequently asked questions
It checks whether untrusted input can change an LLM-powered product’s behavior, misuse a tool, cross a permission boundary, bypass approval, or expose data. The test can include the model, prompts, tools, retrieval system, MCP servers, APIs, and surrounding application.
Yes. Casco agents run the approved tests. A Casco security engineer can also review the scope and findings through Casco Supervised.
Testing can include prompts, tools, permissions, data access, retrieval pipelines, MCP servers, APIs, sandboxes, and the surrounding application when those components are accessible and approved.
Yes. Casco can test direct user input and untrusted content introduced through retrieval, tools, messages, documents, or connected applications when those paths are in scope.
Yes, when the tools, test identities, permissions, approval controls, and safe actions are available. Destructive actions remain prohibited unless the rules of engagement explicitly state otherwise.
Yes, when the retrieval sources, MCP servers, tools, identities, and representative workflows are approved for testing.
A finding can include the triggering input, relevant prompt or tool path, observed result, impact, affected components, fix guidance, reproduction steps, and execution output.
No. Model behavior varies, and a finite test cannot cover every future input or output. The report states what was tested, what was confirmed, and which limitations remain.