Every agent-security vendor tells you what they block. Nobody tells you what they miss.
That gap is the whole problem. "We stop prompt injection" is a claim you cannot check. You cannot run it, and you cannot tell it apart from the next company saying the same sentence. So security engineers do the rational thing and discard all of it.
I published the opposite. It is called the ARE Incident Database, and it is public: https://aredb.org
What is in it
32 agent failures that actually happened, each with a real source. A production database dropped during a code freeze. Twenty-five thousand documents deleted in the wrong environment. Credentials read and shipped to an external sink. A budget burned to zero in a loop.






