Try it
Pick one. The last one is the surprise.
Press a button to start.
Each run prints the agent's tool calls in the order they were recorded, then the decision the server made.
What the full test run found
From the committed results file. The attacks are prompt injections: text planted where the AI assistant reads it, telling it to do something it should not.