Permissions
Checks whether the agent has more access than its task requires.
Identify excessive permissions, shared identities, missing action limits and weak emergency controls.
Checks whether the agent has more access than its task requires.
Reviews how external content can influence tools and actions.
Measures approval gates, limits and potential blast radius.
Evaluates logging, testing and incident containment.