Free test — 2 minutes

Is your AI agent exposed?

Answer 10 questions about your agent: data access, side effects, tools, secrets. Get a risk score and your hardening priorities.

1.Does your agent access a production database or personal data?

2.Can it trigger side effects: sending emails, creating/modifying records, processing payments?

3.Are your users’ inputs injected directly into the model’s context?

4.Does it call external tools (MCP, APIs, code execution) without server-side validation?

5.Can it read or modify other users’ data (multi-tenant)?

6.Do secrets (API keys, tokens, IBAN) appear in its context, logs, or prompts?

7.Is there no limit on the number or cost of its actions (rate limits, quotas, budgets)?

8.You cannot fully trace what the agent did (no action log)?

9.Do its decisions affect billing, subscriptions, or permissions?

10.Has it never been red-teamed (adversarial prompts, prompt injection, tricky texts)?

Your risk score

0/10

Answer the remaining 10 questions to get your score and priorities.

Want to know what your AI agent can do?

Tell us about your agent, its tools, and client context. We will come back with the right review scope.

Discuss your audit