Review agentic AI systems for long-term memory store poisoning, vector DB manipulation, cross-session instruction injection, and stale memory exploitation that persists attacker influence across agent sessions.
Review AI agent systems for agent impersonation, capability escalation, missing agent identity primitives, and authorization failures that allow agents to act beyond their granted permissions or impersonate other agents or human users.
Review organizational defenses against AI-assisted spearphishing, voice cloning, synthetic identity fraud, deepfake executive impersonation, and AI-accelerated reconnaissance that dramatically lowers the barrier to highly targeted social engineering attacks.
Review AI-generated content pipelines for deepfake detection gaps, provenance chain failures, C2PA implementation correctness, synthetic media attribution, and trust signal spoofing that undermines content authenticity verification.
Review AI browser agents for DOM injection attacks, credential harvesting via web automation, malicious web content that hijacks agent actions, session cookie theft, and phishing sites engineered to exploit browser-controlling AI agents.
Review upstream dataset integrity controls, HuggingFace repository risks, dataset versioning, dependency pinning, and third-party dataset provenance to prevent malicious data from entering training or RAG pipelines.
Review AI agent systems for approval step circumvention, human-in-the-loop bypass patterns, deferred confirmation exploitation, and social engineering techniques that cause human reviewers to approve malicious agent actions.
Review inference APIs for credential stuffing, rate limit bypass, quota exhaustion, account takeover, and systematic abuse patterns that exploit the high cost-per-request nature of LLM inference.