Noetfield ABCP — Penetration / security test scope (public) Doctrine: v2.8 Origin: https://banking.noetfield.com Contact: operations@noetfield.com HONEST STATUS - This document is a SCOPE for how ABCP should be tested — not a completed pen-test REPORT. - We do not publish fabricated findings or fake PDF certificates. - When an independent test is completed for a contracted environment, the report is shared under NDA via the data room process. IN SCOPE (agent money control plane) 1. Prompt injection → money tool (create_payment / similar) 2. Confused deputy / cross-tenant write 3. SSRF via tool arguments (invoice URLs, callbacks) 4. Secret echo / credential leakage in tool args or logs 5. Loop / drain against per-tx and daily limits 6. High-value action without confirm 7. Confirm token replay 8. Kill switch / suspend-agent effectiveness 9. Receipt tamper evidence (Ed25519 verify against published key) 10. Authn/authz on live gateway APIs (contracted env only) OUT OF SCOPE (this public Worker) - Live money movement (this surface does not move money) - Social engineering of Noetfield staff - DoS against third-party model providers - Testing licensed rail partners without their written authorization PUBLIC EVIDENCE - Threat model: https://banking.noetfield.com/security - Eval twin: sec.money_v1 (agent-security-bench) - Receipt schema: https://banking.noetfield.com/schema/receipt-money-v1.json - Verify example: POST https://banking.noetfield.com/v1/receipts/verify REQUEST FULL REPORT / ENGAGEMENT Email operations@noetfield.com with subject: ABCP pen-test / NDA data room