Publishable evidence
AI agent findings need enough context to be useful, but prompt transcripts can become reusable attack material.
- Describe the failed boundary: instruction hierarchy, source trust, or tool authorization.
- Include the expected control and the observed deviation.
- Map to OWASP LLM categories when the mapping helps remediation.