Select what your agent can access. This builds a small, non-destructive test plan for retrieved content, MCP tool results, write actions, credentials, scopes, and audit evidence.
Generate my test planThe $12 kit expands this into 24 regression scenarios plus a 45-control audit workbook, permission matrix, evidence ledger, launch gate, incident runbook, and policy starter.
Prompt injection becomes more consequential when instructions arrive through content the model did not author: a retrieved document, webpage, email, database record, MCP tool response, or tool description. A useful regression test verifies that untrusted content cannot silently cross important authorization boundaries.
Use a harmless marker such as CANARY-7421 to represent protected data or a prohibited action. Do not expose real secrets or modify real systems merely to prove the test works.
An assistant can verbally reject an instruction while still invoking a tool. Record both the model response and tool calls. High-impact actions should remain behind explicit approval with the exact proposed parameters.
Tests should verify that untrusted content cannot rewrite tool schemas, broaden scopes, introduce destinations, or disable approval requirements.
Repeat the same cases when models, prompts, MCP servers, tool descriptions, permissions, or retrieval sources change. Regression evidence is more useful than a one-time demonstration.
Defensive testing aid, not a security certification. Test only systems you own or are authorized to assess.