# UndercoverAgent.ai > Agent testing and evaluation platform. Reports test evidence for AI-agent failures before your customers do. UndercoverAgent is built by David Hurley (https://dbhurley.com), founder of Plasmate Labs and creator of the Adaptive Convergence Protocol (ACP) framework. ## About UndercoverAgent is an automated testing platform that acts as a "secret shopper" for AI chatbots and agents. It simulates real customer interactions through multi-turn conversations and reports test evidence for failures, security issues, quality problems, and hallucinations. ## Key Capabilities - Multi-turn conversational testing against deployed AI agents - 11+ analysis passes: security, compliance, quality, adversarial safety, hallucination detection, escalation risk, and more - Connectors for REST APIs, web chat widgets, and Slack bots - Scheduled continuous monitoring with regression detection - CI/CD integration via API with test quotas and billing - YAML/JSON scenario library with 20+ pre-built test suites ## API - Base URL: https://undercoveragent.ai/api/v1 - Authentication: Bearer token (API key) - POST /api/v1/tests/run — Trigger a test run - GET /api/v1/tests/{id} — Get test result ## Machine-readable discovery - Canonical discovery document: https://undercoveragent.ai/.well-known/llms.txt - Legacy alias: https://undercoveragent.ai/llms.txt - OpenAPI specification: https://undercoveragent.ai/api/openapi ## Public paid offer - Weekly Brief Retainer: $500/week — One weekly intelligence brief on your live AI agent - Buy page: https://undercoveragent.ai/weekly-brief - Sales landing: https://undercoveragent.ai/retainer - Checkout: GET https://undercoveragent.ai/api/stripe/weekly-brief (no sign-in required) This is test evidence, not a legal certification or a guarantee that an agent is safe. Authenticated monthly test-quota upgrades are not the public offer. ## Blog Categories - AI Testing & QA (97 articles) - Security (11 articles) - CI/CD & DevOps (27 articles) - Industry & Insights (3 articles) ## Recent Articles - [Watching the Chat Is Not a Weekly Brief](https://undercoveragent.ai/blog/watching-the-chat-is-not-a-weekly-brief) (2026-08-29) — Spot-checking chats, screenshots, and last month's eval are not this week's product. The job is a written weekly brief with transcript-backed findings. - [Your Model Pin Will Not Survive September 1](https://undercoveragent.ai/blog/your-model-pin-will-not-survive-september-1) (2026-08-27) — Labor Day week Git stays frozen while the September 1 vendor control plane still ships. A pinned model ID and green main are not the same product. - [Your Users Changed This Week. Your Diff Didn't.](https://undercoveragent.ai/blog/your-users-changed-this-week-your-diff-didnt) (2026-08-26) — A green Git repo is not a stable LLM product. Back-to-school traffic and floating model aliases changed what you shipped this week, with no pull request. - [Your Code Freeze Doesn't Freeze the Model](https://undercoveragent.ai/blog/your-code-freeze-doesnt-freeze-the-model) (2026-08-23) — A code freeze locks Git before Labor Day. Vendor defaults and routing weights keep moving. Your last observed behavior is already a stale baseline. - [Your Git History Is Lying About What Shipped](https://undercoveragent.ai/blog/your-git-history-is-lying-about-what-shipped) (2026-08-20) — A quiet repo is not proof production is unchanged. Post-Black Hat MCP write-ups show capability-graph drift with zero commits. - [Your Model Card Is Not Your Conformity Artifact](https://undercoveragent.ai/blog/model-card-is-not-conformity-artifact) (2026-08-19) — Two weeks after 2 August 2026, vendor model cards are being filed as high-risk proof. They describe a component. Customers use a composed, drifting product. - [Your AI Dependency Changed. Did Your Gate Notice?](https://undercoveragent.ai/blog/ai-dependency-changed-quality-gate-notice) (2026-08-13) — The LiteLLM breach exposed more than credentials. It showed why AI reliability controls must detect behavior changes beyond application code diffs. - [The Gym Hack: Permissions Set the Blast Radius](https://undercoveragent.ai/blog/gym-hack-permissions-blast-radius) (2026-08-12) — A Claude agent exploited a gym booking workflow. The real lesson is that permissions, tools, and defaults now shape product reliability. - [OpenAI's Cyber Model Makes QA a Security Control](https://undercoveragent.ai/blog/openai-cyber-model-makes-qa-security-control) (2026-08-11) — OpenAI's new cyber model changes the QA burden for AI application owners. Static scans are not enough when attackers can adapt faster than test suites. - [A Safer Model Won't Fix Your Crisis Flow](https://undercoveragent.ai/blog/safer-model-wont-fix-crisis-flow) (2026-08-10) — Crisis safety depends on prompts, memory, escalation, and handoffs, not just the model behind your conversational AI. - [Astra’s Pause Is Your Release Warning](https://undercoveragent.ai/blog/astras-pause-is-your-release-warning) (2026-08-09) — OpenAI’s Astra pause shows why provider safeguards are not enough. Every team embedding a model needs release gates for behavior, tools, prompts, and drift. - [Your AI's Biggest Release May Skip Git](https://undercoveragent.ai/blog/your-ais-biggest-release-may-skip-git) (2026-08-09) — Anthropic's Claude Code default change exposes a control gap: AI behavior can shift without a commit, while CI keeps checking yesterday's assumptions. - [Your AI's Behavior Has a Supply Chain](https://undercoveragent.ai/blog/ai-behavior-supply-chain) (2026-07-26) — Model providers are rotating and deprecating snapshots all summer. Your prompt didn't change, but your production behavior did. Here's the category nobody named yet. - [Explainability: The Key to Trustworthy AI Quality Assurance](https://undercoveragent.ai/blog/explainability-ai-quality-assurance) (2026-07-07) — Integrating explainability into AI quality assurance meets regulatory demands and builds user trust, enhancing overall system performance. - [Exploring the Link Between AI Security Funding and Quality Assurance](https://undercoveragent.ai/blog/ai-security-funding-quality-assurance) (2026-07-06) — As AI security funding surges, the need for robust quality assurance is often overlooked. Here’s how to balance both for effective AI systems. - [AI Security Demands Quality Assurance Investment](https://undercoveragent.ai/blog/ai-security-quality-assurance-investment) (2026-07-06) — As AI security funding rises, integrating quality assurance is vital to prevent vulnerabilities. Explore the critical synergy between these areas. - [Why Quality Assurance is Essential for AI Security Funding](https://undercoveragent.ai/blog/quality-assurance-ai-security-funding) (2026-07-05) — As AI security investments surge, quality assurance must be prioritized to ensure robust and secure AI systems against evolving threats. - [Why Your AI Quality Assurance Strategy Needs a Security Overhaul Now](https://undercoveragent.ai/blog/ai-quality-assurance-security-overhaul) (2026-07-04) — The recent $64M funding for AI security underscores the urgent need for integrating security into your AI quality assurance strategy. - [Why AI Security Funding Demands Stronger QA Measures](https://undercoveragent.ai/blog/ai-security-funding-qa) (2026-07-03) — With Straiker's $64M funding, the urgency for robust QA frameworks in AI is clearer than ever. Here’s why QA is essential for secure deployments. - [Why Quality Assurance is Your Best Defense Against AI Vulnerabilities](https://undercoveragent.ai/blog/quality-assurance-ai-security) (2026-07-02) — As AI security funding rises, quality assurance must play a critical role in safeguarding AI deployments from vulnerabilities and adversarial threats. - [AI Accountability: The QA Challenge Ahead](https://undercoveragent.ai/blog/ai-accountability-qa-challenge) (2026-06-08) — As AI regulations tighten, companies must revamp their QA strategies to ensure compliance and build user trust. Here's how to get ahead. - [Overcoming AI Evaluation Hurdles: A Guide for Technical Leaders](https://undercoveragent.ai/blog/overcoming-ai-evaluation-hurdles) (2026-06-07) — Many leaders focus on AI capabilities, but real challenges lie in evaluation and integration. Explore actionable strategies for success. - [Rethinking Quality Assurance in Local AI Processing](https://undercoveragent.ai/blog/rethinking-quality-assurance-local-ai-processing) (2026-06-06) — As Nvidia brings AI to personal computers, organizations must adapt their QA strategies for localized processing to ensure reliability and trust. - [Exploring Apple's AI Innovations: Quality Assurance Impacts](https://undercoveragent.ai/blog/apple-ai-innovations-quality-assurance) (2026-06-05) — Apple's upcoming AI advancements raise critical quality assurance challenges. Technical leaders must adapt their QA strategies to keep pace. - [Exploring Local AI: How Nvidia's New Chip Demands a Rethink in Quality Assurance](https://undercoveragent.ai/blog/exploring-local-ai-quality-assurance) (2026-06-05) — The shift to local AI processing raises critical questions for quality assurance. Here's how to adapt your strategies for emerging challenges. - [Apple's AI Innovations: A Quality Assurance Wake-Up Call](https://undercoveragent.ai/blog/apples-ai-innovations-quality-assurance) (2026-06-04) — Apple's upcoming AI advancements may redefine quality standards in conversational interfaces, compelling AI developers to elevate their QA practices. - [Investing in AI Quality Assurance: A Smart Move](https://undercoveragent.ai/blog/investing-ai-quality-assurance-smart-move) (2026-06-03) — A recent $16M funding surge underscores the strategic importance of quality assurance in AI. Here’s why your organization should prioritize it. - [How Anti-Tech Sentiment Could Shape AI Quality Assurance](https://undercoveragent.ai/blog/impact-of-anti-tech-sentiment-ai-quality-assurance) (2026-06-02) — As anti-tech sentiment rises, AI quality assurance must adapt to align with public concerns and ethical standards. Here’s how to navigate this shift. - [Is Your AI Ready for the Backlash? Navigating Anti-Tech Sentiment](https://undercoveragent.ai/blog/ai-backlash-sentiment) (2026-06-01) — The rise of anti-tech sentiment poses new challenges for AI development. Here’s how to navigate this critical landscape for quality assurance. - [Is Your AI Customer Support Missing the Human Touch?](https://undercoveragent.ai/blog/ai-customer-support-human-touch) (2026-05-31) — Explore how companies can balance AI efficiency with the essential human element in customer support interactions. ## Links - Website: https://undercoveragent.ai - Weekly brief: https://undercoveragent.ai/weekly-brief - Retainer: https://undercoveragent.ai/retainer - Blog: https://undercoveragent.ai/blog - Demo: https://undercoveragent.ai/demo - Dashboard: https://undercoveragent.ai/dashboard - GitHub: https://github.com/dbhurley/undercoveragent - JSON Feed: https://undercoveragent.ai/api/blog/feed.json ## Founder - Website: https://dbhurley.com - Related writing: https://dbhurley.com/blog/the-evaluation-function-is-the-product - Related writing: https://dbhurley.com/blog/what-an-ai-agency-actually-needs ## Contact hello@undercoveragent.ai ## Part of the DBH Ventures portfolio https://dbhurley.com/startups