New AI Penetration Testing Framework Covers Prompt Injection, Data Poisoning, and Agentic Tool Misuse