Prove, report,
then block.
One object: the action — what your agent executes through its tools. We prove it can be hijacked, we document every scene, and the ActionShield software will cut the action before the tool. Always on your sandbox, never on prod without a mandate.
The framework
The three steps
The proof (20 minutes)
On your sandbox: we show one action your agent should not be able to take. If we find nothing, you pay nothing. Fear is not announced, it is demonstrated.
The report (5 days)
Tool and action inventory, documented injection scenes, attempted exfiltration chains, business-impact prioritization. Reusable as-is in your client questionnaires.
The layer (the software, soon)
The ActionShield software: the proxy in front of your tools — in spec, allow; out of spec, block + journal. In development, tested early by design partners.
What we attack, exactly
Injection through read content
A ticket, a document, a resume, a dependency README: any text your agent reads can carry an instruction — and it obeys.
Tool poisoning
An instruction hidden in a tool's description or return — typically an MCP server your agent calls without reading it fully.
In-spec exfiltration
The attack that goes through allowed actions: a legitimate mail whose body contains what a sensitive tool just read. The scene no naive allowlist cuts.
Perimeter abuse
The gap between mounted tools and granted tools: what your agent can access, who decided, and where it is written. Nowhere, usually.
The rules of engagement
- Sandbox provided and controlled by the client — the provided access is the mandate.
- Systematic written authorization before any mission.
- Zero data retention, documented cleanup.
- Responsible disclosure aligned with ISO 29147.
- Findings mapped to OWASP Top 10 for Agentic Applications (ASI02, ASI03) and MITRE ATLAS (AML.T0053).
- Zero attribution in test artifacts: nothing traceable to the operator.
What we never do
- No testing on your production without written mandate.
- No scanning of third-party systems, no unauthorized access.
- No massive data extraction — we confirm readability, we stop.
- No modification of your real data.
What you receive
The report
Short, readable, written for your client questionnaires and your team — every finding with its reproducible proof and what would have cut it.
The action spec
Black on white: what your agent is allowed to do, tool by tool, argument by argument. The deliverable nobody else produces.
The layer (soon)
The ActionShield software deployed on your side: every action checked against the spec, every decision journaled. Design partners test it first.