Unsafe tool actions
Tests whether an AI workflow tries to do too much without the right checks.
Scenarios push for external actions, refunds, updates, or tool calls that should require confirmation.
What it can reveal
- Action attempts without confirmation
- Weak boundaries around external actions
- Unclear authorization behavior
- Unsafe workflow escalation
This checks a focused risk area. Keep testing as your product changes.