Evidence-based security review for tool-using AI

AI Agent Security Assessment

Run an AI agent security assessment that maps what the agent can access, what can influence it, what actions it can take and what evidence supports a deployment decision.

5–10 minutes for the first check No card to start £99 once for the full assessment package
Useful before launch, customer review or expanded authority MCP agentsTool-using agentsAutonomous workflowsCustomer-facing agentsInternal agents
What changes the risk

“AI agent” is not one security profile.

An assistant that drafts text is different from an agent with persistent memory, MCP tools, scheduled execution, customer data, financial authority or the ability to delegate work to other agents.

01

Authority

Can the agent only recommend, or can it write records, send messages, change permissions, deploy code or move money?

02

Influence

Can users, email, files, websites, tool output or stored memory inject instructions into the workflow?

03

Autonomy

Does it act only when asked, or can it run on schedules, react to events, replan, chain goals or continue without immediate approval?

04

Recovery

Can policy, memory, tooling, workflow and changed data be rolled back after a bad or manipulated action?

What the assessment covers

What an AI agent security assessment checks before deployment.

The review follows the same evidence chain used inside AgentRiskLayer. Capabilities can make controls relevant, but they do not become vulnerabilities by themselves.

1
PROFILE

Agent capabilities

Record autonomy, memory, tool discovery, delegation, trigger mode, learning or adaptation, evaluator authority and recovery scope.

2
ACCESS

Data and permissions

Review identities, tenant scope, customer data, secrets, files, databases, networks and administrative access.

3
TOOLS

MCP and action surface

Review tool trust, dynamic discovery, external services, write authority, action validation and downstream enforcement boundaries.

4
ATTACK

Prompt injection and misuse

Test authorised scenarios where untrusted input tries to influence tool calls, approvals, data access or protected actions.

5
CONTROL

Human approval and runtime policy

Check whether high-impact actions are bound to the exact action, target, parameters, value and validity period before execution.

6
PROVE

Evidence, remediation and retest

Connect observed controls, test evidence, findings, remediation ownership, exact retest and the resulting deployment decision.

Evidence model

A security claim is not the same as security evidence.

AgentRiskLayer keeps each stage separate so missing information is not silently converted into a vulnerability and a declared safeguard is not treated as verified control evidence.

  1. 1
    DECLARE

    Declared controls and capabilities

    The owner describes the exact agent version, its access, tools, autonomy, approvals and safeguards.

  2. 2
    OBSERVE

    Observed controls and tests

    Code, configuration, inspection output, authorised tests and runtime records are collected separately from declarations.

  3. 3
    FIND

    Findings only when supported

    A finding requires an observed or reproducible failure. Unknown, missing or inconclusive information remains an information gap.

  4. 4
    DECIDE

    Fix, retest and decide

    Remediation is recorded, the exact failure is retested and current evidence supports a proceed, hold or do-not-deploy decision.

Example assessment question

An MCP-enabled support agent can issue refunds. What proves the action is controlled?

A useful answer needs more than “human approval is enabled.” The assessment checks where approval is enforced, what exact action and value are bound to it, whether it can be replayed, what happens when parameters change and what evidence records the decision.

Assessment rule PROVE IT

Capability → applicable control → test → evidence → finding only if failure is demonstrated.

Unknown information?
Context required
Failed test?
Finding path
Fix recorded?
Exact retest
Start with one agent

Free qualification first. Evidence workflows when you need them.

The free check identifies what needs review. The £99 AI Agent Security Assessment unlocks the full report and customer-operated inspection, controlled-testing, remediation and retest workflows. It reports only work actually completed.

QUALIFY

Free agent check

£0

Describe the agent, its access and safeguards and get an initial risk view.

Start free
OPERATE

Runtime protection

From £29 /month

Ongoing projects, runtime decisions, retention and team workflows.

Compare plans
Questions buyers and builders ask

AI agent security assessment FAQ

Is this a certification?

No. AgentRiskLayer Security Assessment is a proprietary assessment against the AgentRiskLayer Control Profile. It is not an accredited certification or a guarantee that a system is risk-free.

Does an unknown capability become a finding?

No. Unknown or unconfirmed information remains context. A finding requires an observed or reproducible control failure.

Can the assessment cover MCP agents?

Yes. The assessment can review MCP and other tool-enabled agents, including tool trust, permissions, external dependencies, action validation, prompt injection exposure and approval boundaries.

What happens after a finding is fixed?

The remediation is recorded against the changed system version and the exact original failure is retested before closure.

Do I need to expose secrets?

No. The assessment is designed around privacy-safe descriptions and evidence. Do not enter credentials or secrets into the assessment fields.

Assess one real agent

Find out what it can do and what evidence you still need.

Start free. Unknowns remain unknown. Findings require evidence.

Start the AI agent security assessment