Skip to content
winfunc
AI security

Security for the AI features you ship.

Find prompt injection, excessive agency, data leakage, and unsafe tool use in LLM applications and agents, traced from untrusted input to the action it can trigger and proven in a sandbox.

What's included
  1. acme
  2. /support-agent
  3. /Vulnerabilities
  4. /WF-1177
Critical
Sourceinbox/ingest.ts:31
ticket.body
Sourceinbox/ocr.ts:58
attachment.text
1
Untrusted text placed in the model's context as instructionsmessages.push({ role: "user", content: ticket.body })agent/run.ts:44
2
Refund tool exposed without a human approval steptools: [lookupOrder, issueRefund]agent/tools.ts:12
Sinkagent/tools/refund.ts:27
await stripe.refunds.create({ charge, amount })

Customer ticket text can make the support agent issue refunds

CriticalCVSS 9.0
Weakness
OWASP LLM01 · Prompt injection
Confidence
97
Validation
Exploitable
Proof
A crafted ticket triggered a refund in the sandbox
Finding · source to sinkIllustrative data
The problem

Your model reads untrusted text. Your tools trust your model.

Support agents, copilots, and retrieval features turn customer content into instructions, then hand the model tools that act on them. winfunc traces untrusted input through prompts, retrieved documents, and tool calls to the operation it can reach, and proves the path in an isolated environment.

Included

What winfunc covers.

  • Direct and indirect prompt injection through user input, files, and retrieved content
  • Excessive agency: tools and permissions reachable from model output
  • Sensitive data exposure through prompts, context windows, logs, and responses
  • Insecure output handling where model output reaches code, queries, or HTML
  • Authorization around agent actions and tenant isolation in retrieval
  • Findings mapped to the OWASP Top 10 for LLM Applications
  • Fixes such as approval steps, tool allow-lists, and output validation opened as pull requests
Outcomes

What your team walks away with.

01

Traced to the action

Each finding follows untrusted text to the tool call, query, or payment it can trigger, with the code at every hop.

02

Proven, not theorized

Injection paths are reproduced in a sandbox with harmless payloads, so severity reflects what actually happens.

03

Guardrails in code

Fixes land where they hold: permission checks, approval steps, and validation around the model, not only prompt wording.

04

Keeps pace with the product

Pull-request review catches new tools, prompts, and retrieval sources as the AI feature evolves.

Continue the evaluation

Start with one repository

Bring us your hardest codebase.
We'll bring the proof.

Scope a first audit with our security engineers. You get findings with traces, reproduction evidence, and patches ready for review.

Scoped with you. Delivered with evidence.

A voxel chessboard: a bone rook and a red knight, with the traced path between them lit green after the fix was verified