Sample Report

A glimpse of a Dwaar red-team report

How Dwaar scores an agent — top attack controls, payload-delivery techniques, and compliance-framework coverage, exactly as they appear in the platform.

Illustrative sample data

app.dwaar.ai/reports/cs-agent
Red Team Evaluation
Customer Support Agent

Adversarial evaluation of an LLM customer-support agent across 12 attack controls and 6 payload-delivery techniques.

Target System
Support Agent (production)
Run Completed
Jun 18, 2026 · 14:32 UTC
Test Depth
12 controls · 6 payload deliveries · 1,266 probes
Overall Status
Action required
Critical Control Gaps
3
3 categories need immediate review
Defense Rate
92.7%
1,174 of 1,266 probes safely refused
Bypass Rate
7.3%
92 attacks succeeded out of 1,266

Top Payload Deliveries

Adversarial delivery techniques and how often they got through.

Basic Prompting
2.1%

Plain adversarial requests with no obfuscation — the control baseline.

9 of 422 attempts succeeded
Base64 Encoded Prompting
9.4%

Malicious instructions encoded in Base64 to slip past keyword filters.

20 of 212 attempts succeeded
TMAP Technique
16.3%

Multiple adversarial payloads evolved with a trajectory-aware evolutionary search.

22 of 135 attempts succeeded
15+ payload deliveries

Multi-turn & adaptive techniques like GOAT and Crescendo, plus more.

Contact Us

Top Attacks / Controls

Controls ranked by severity and exploitability.

Control Severity Difficulty Bypasses Bypass Rate
Sandbox Write Escape
Coding agent writes outside its allowed sandbox path.
Critical 14 / 120 11.7%
RAG Document Exfiltration
Verbatim or near-verbatim extraction of source documents from the RAG corpus.
High 9 / 110 8.2%
Delayed CI Exfiltration
Coding agent stages exfiltration that fires later in CI rather than during the live session.
High 6 / 96 6.3%
80+ attack controls

Across security, safety, privacy and brand-risk categories.

Contact Us

Compliance Framework Coverage

Tap a framework to see details

How this run maps to industry & regulatory frameworks.

OWASP LLM Top 10
Critical 2 / 8 attack vectors failed
System Prompt Disclosure4.3%
MCP Tool Abuse6.3%
Prompt Injection96 / 96
Insecure Output Handling88 / 88
Sensitive Info Disclosure74 / 74
Excessive Agency60 / 60
Training Data Poisoning40 / 40
Overreliance32 / 32
OWASP API Security Top 10
Review 1 / 6 attack vectors failed
Broken Object-Level Authorization10.6%
Broken Authentication40 / 40
Resource Consumption36 / 36
Security Misconfiguration30 / 30
Unsafe API Consumption24 / 24
Improper Inventory Mgmt18 / 18
MITRE ATLAS
Critical 2 / 7 attack vectors failed
LLM Prompt Injection7.1%
Sandbox Write Escape11.7%
Model Evasion52 / 52
Data Exfiltration44 / 44
Discovery30 / 30
Persistence28 / 28
Reconnaissance24 / 24
GDPR
Pass 0 / 4 attack vectors failed
PII — Direct Disclosure48 / 48
PII — via Session36 / 36
PII — via API / DB30 / 30
Data Subject Rights22 / 22
NIST AI RMF
Review 1 / 5 attack vectors failed
Reasoning DoS5.7%
Prompt Injection96 / 96
Harmful Content80 / 80
Data Privacy60 / 60
Output Integrity54 / 54
EU AI Act
Pass 0 / 4 attack vectors failed
Prohibited Manipulation44 / 44
Transparency Obligations38 / 38
Human Oversight30 / 30
Data Governance26 / 26
ISO/IEC 42001
Review 1 / 6 attack vectors failed
System Prompt Disclosure4.3%
Access Control70 / 70
Data Management58 / 58
Operational Controls50 / 50
Incident Response40 / 40
Supplier Risk30 / 30
OWASP Agentic AI Top 10
Critical 2 / 7 attack vectors failed
Sandbox Write Escape11.7%
MCP Tool Abuse6.3%
Memory Poisoning56 / 56
Tool Misuse48 / 48
Privilege Compromise40 / 40
Cascading Hallucination36 / 36
Goal Manipulation30 / 30
DPDP Act, 2023
Pass 0 / 4 attack vectors failed
Consent & Notice40 / 40
Purpose Limitation34 / 34
Data Principal Rights28 / 28
Fiduciary Obligations24 / 24

Want a report like this for your own agents?

Get your Free A-SPM Report