AI & LLM Security Assessment
Your agents hold credentials, browse, and execute. We attack them the way adversaries already are โ prompt injection, skill compromise, exfiltration โ then show you how to contain it.
What we cover
- Prompt injection: direct, and indirect through retrieved or uploaded content
- Data exfiltration paths: rendered Markdown, tool outputs, links, image loads
- Tool, MCP, and skill permission review โ least privilege in practice
- Memory and RAG poisoning, persistence, and context abuse
- Guardrail and output-handler bypass testing
- Agent identity, credential scoping, and blast radius
- Mapping to the OWASP Agentic AI and LLM Top 10
How we test
We chart every agent, tool, skill, data source, and trust boundary โ most teams have never seen this drawn out. It ships with the report.
Static analysis of what each component can reach: files, network, credentials, production data. Over-privilege is the #1 finding.
Live injection, exfiltration, and privilege-abuse testing against a controlled tenant or staging copy โ never your real data.
Isolation, egress filtering, identity scoping, output handling โ then a re-review once changes land.
What you get
- Agent attack-surface map with trust-boundary diagram
- Findings ranked by demonstrated exfiltration impact
- Hardening guide: isolation, egress, identity, output handling
- Developer-focused fix guidance and a re-review
The engagement at a glance
A short conversation about your environment. You receive a written scope, timeline, and fixed quote โ no obligation.
Testing begins only with your written permission and agreed rules of engagement. Always.
A calendar agreed before we start, with an agreed communication plan while testing runs.
A verification pass over everything you fix โ included in the price, not an add-on.
See the full engagement process โ and how pricing is scoped in our public pricing guide.
Related research from Hmmnm
Common questions
We use enterprise Copilot or ChatGPT, not custom agents โ can you still assess us?
Yes. The assessment then focuses on configuration, data connectors, consent grants, and how AI features integrate with your systems โ the parts you control.
Does testing risk our production data?
No. Exfiltration testing runs against controlled tenants or staging copies with synthetic data. We never move real data out of your environment.
Which frameworks do you map findings to?
The OWASP Agentic AI Top 10 and OWASP Top 10 for LLM Applications, plus MITRE ATLAS where it fits your stack.
Want this assessed for your environment?
A short scoping conversation is enough to get a fixed quote. No obligation โ a researcher replies.
Start the conversation โ