Red teaming deliberately searches for ways the complete system can violate its requirements; evaluation measures those requirements repeatedly. Attack every trust boundary—input, retrieval, tools, MCP, state, approvals, adapters, queues, telemetry, and operators—then preserve sanitized failures as regression cases. A one-time penetration session is not a durable safety program.
You will execute a structured attack plan, triage failures by impact, and connect mitigations to tests and release gates.
Report attack success rate by category, unauthorized-effect count, data exposure, detection rate/time, containment time, quality impact of defenses, false positive approvals/denials, and residual risk. Never hide a critical breach inside an average.
Failure injection: Attempt to make an injected knowledge article approve its own mutating tool call. The harness policy should deny or require real approval regardless of model behavior.
Invite a separate reviewer to attack SupportOps from a threat model without seeing your cases. Compare coverage and add missing attack classes to the suite.