Type an instruction a malicious user might send a production AI agent — move money, wipe data, leak a secret, override the rules. Watch what the runtime controller does. Then verify the decision yourself, in your own browser. No dashboards. No trust required.