They tried. It didn't work that well:
How did you managed to get it to do that? When I gave it instructions to use Ghidra MCP to look for vulnerabilities in a windows driver on my local machine it refused saying it's not allowed to do pentest activities even if sandboxed to your own device.
Sorry, can you clarify what you're saying here? What didn't work that well?