CASE 01 · Action chain exploitation
Every call is legitimate. The sequence is the attack.
What the guardrail read
“Pull the Q3 vendor list, check which contracts renew this month, and prep the renewal summaries for finance.”PASSED
The prompt has no injection and no sensitive data, so a filter has nothing to flag.
Where agent actions became threats
Action sequence · Ackuity security verdicts
db.read vendors.q3ALLOWEDdb.read contracts.renewalsALLOWEDiam.role.assume finance-adminCONSTRAINEDapi.post payments.batchBLOCKEDemail.send cfo@ "renewals done"BLOCKED

