What the audit must cover
Audit the application and the agent together: identity, authentication, authorization, tenant isolation, data access, MCP and API tools, memory, uploaded content, payment flow, secrets, logs, limits, approval, and recovery. A safe prompt cannot compensate for a broken access check or payment path.
Set written scope, test identities, allowed methods, hours, stop conditions, evidence handling, and owner approval before active work. Never point an automated scanner or exploitation attempt at a live platform without explicit authorization.
Treat the result as a dated risk snapshot, not a certificate of absolute security. Fix by business impact, retest the exact behavior, and repeat after material changes to access, tools, memory, payments, models, or infrastructure.