A practical methodology for security testing AI agents and LLM applications. What to test, how to prioritize, and how to interpret the results.