What breaks in production is usually boring: an API key left in an agent’s config, a shell or SQL tool that runs whatever the model says
(prompt injection is the first entry in the OWASP Top 10 for LLM apps),
tool calls with no timeout, a service failing silently because nothing traces it, and a cloud or AI bill nobody can explain.
That last one is growing: in a CloudZero survey of 260 finance leaders (June 2026),
87% said they need to tie AI spend to business outcomes within a year, but only 22% can today.
Checking for these is cheap. The catch is that the files you’d check are full of secrets. As an SRE, I wanted a first pass that never
leaves the browser tab, so these tools have no backend. They’re heuristics, not an audit.
GLP-1 Support is for a different gap: most patients get medication instructions, but most aren’t referred to any other support.
Read why it exists.