
Why Multi-Step Drift Isn't Required for Runtime Risk
We attempted to induce multi-step MCP agent drift across monitoring and AWS tools. The experiment didn't produce reliable chains—but it revealed why the very first unexpected tool call is already a runtime security decision.











