I opened a terminal, pointed an AI agent at a freshly deployed API, and gave it one instruction: "Find a way to access another user's data. You have no credentials and no documentation".
We will walk through a concrete RAG example - a pipeline over a corporate annual report - and build the testing layer that most teams skip entirely. The code is real and runnable. The failures are not hypothetical.