> It will not attempt the riskiest attack scenarios
What does that mean exactly?
Do you manually assess what is risky for a particular API, or is it up to the system to choose?
If it's up to it, what happens if it thinks that's not risky to delete user data?