These are illustrative demonstrations of how ordinary requests can produce unintended results — awareness examples, not attack instructions. They contain no working exploit code.
The serious ones live in your configuration — permission inheritance, automation identity, injection paths. A structured review maps them against your actual environment under NDA, with findings your auditors and board can use.
This automated triage is informational only and is based solely on the selections you provided. It is not an audit, security assessment, legal advice, or professional opinion, and it does not establish an engagement or duty of care. Findings describe categories of risk commonly associated with the indicated configurations; your actual exposure depends on facts not collected here.
We collect real-world accounts of AI, automation, and control failures around financial systems and compile them — anonymized — into our detection ruleset. What happened, which systems were involved, what the control gap was, and how (or whether) it was caught. Contributors of substantive casework may be invited into our contributor program as it develops. Do not include company names, personal names, account data, or documents you are not authorized to share.
Submissions are voluntary and treated as confidential. Until our dedicated anonymous intake is live, submitting opens your email application — which shares your email address with us; leave the contact field blank and use a personal device if that matters to you. This is not a legal whistleblower channel: reports to regulators (e.g., the SEC or IRS whistleblower programs) carry their own legal protections and processes, and nothing here substitutes for them or for advice from a lawyer. If you are bound by an NDA or confidentiality obligation, get legal advice before sharing specifics.