Traced to the action
Each finding follows untrusted text to the tool call, query, or payment it can trigger, with the code at every hop.
Find prompt injection, excessive agency, data leakage, and unsafe tool use in LLM applications and agents, traced from untrusted input to the action it can trigger and proven in a sandbox.
messages.push({ role: "user", content: ticket.body })agent/run.ts:44tools: [lookupOrder, issueRefund]agent/tools.ts:12Customer ticket text can make the support agent issue refunds
Support agents, copilots, and retrieval features turn customer content into instructions, then hand the model tools that act on them. winfunc traces untrusted input through prompts, retrieved documents, and tool calls to the operation it can reach, and proves the path in an isolated environment.
Each finding follows untrusted text to the tool call, query, or payment it can trigger, with the code at every hop.
Injection paths are reproduced in a sandbox with harmless payloads, so severity reflects what actually happens.
Fixes land where they hold: permission checks, approval steps, and validation around the model, not only prompt wording.
Pull-request review catches new tools, prompts, and retrieval sources as the AI feature evolves.
Continue the evaluation
Scope a first audit with our security engineers. You get findings with traces, reproduction evidence, and patches ready for review.
