AI Security

AI Agent Permission Auditor

Audit what an autonomous agent can actually do, covering tool scope, identity, the boundary between untrusted content and instructions, and the controls that make agent actions reviewable.

Last reviewed by the Radiatus Cloud team

Results appear here.

Securing AI in production?

We build guardrails, governance & compliance for AI systems.

Talk to an AI advisor

An agent is its tools, not its prompt

The security properties of an agent deployment are determined almost entirely by what the tools can do and what credentials they carry. A system prompt instructing the model not to delete anything is a request; a credential without delete permission is a control. This distinction gets lost because prompts are visible and easy to change while permissions live in a different system, so the review that happens is a review of the prompt, which is the half that cannot enforce anything.

Prompt injection is a structural problem, not a filtering one

When retrieved documents, emails, web pages or tool output are concatenated into the same context as the operator's instructions, the model has no reliable way to distinguish them, because there is no channel separating them. Every mitigation applied at the instruction level, telling the model to ignore instructions in retrieved content, is asking the model to solve a problem the architecture created. The durable defences are structural: keep untrusted content out of the instruction channel, validate what comes back before it reaches a tool, and scope the tools so that a successful injection reaches something harmless.

Borrowed identity destroys attribution

Agents are commonly deployed using an existing service account or, worse, a named employee's credentials. Every action then appears in every downstream log as that principal, so an investigation cannot separate what a person did from what an agent did on their behalf, and revoking the agent's access revokes the person's. Giving the agent its own identity costs almost nothing at deployment and is close to impossible to retrofit after an incident.

Related tools

Frequently Asked Questions

Why does the system prompt not count as a control?

Because it is a request rather than an enforcement point. A model can be persuaded to disregard it, whereas a credential without delete permission cannot delete regardless of what the model decides.

Can prompt injection be filtered?

Not reliably. It is a structural problem created by merging untrusted content into the instruction channel, and instruction-level mitigations ask the model to solve a problem the architecture created. The durable defences are separation, output validation and tool scoping.

Why should an agent have its own identity?

Because an agent using a person’s credentials is indistinguishable from that person in every log, so attribution fails exactly when it matters, and revoking the agent removes the person’s access too.

Does human approval solve the problem?

Only if the reviewer sees what will actually happen. A confirmation step that displays the model’s own description of its action approves the description rather than the action.

Is unrestricted network access a real risk?

Yes. Unrestricted fetch is an exfiltration channel, because content the agent has read can be encoded into a URL it is persuaded to request. An allowlist closes it without removing the capability.

Privacy & Security

Everything runs in your browser; nothing is uploaded.

Data: None
Client-side-Side
Active
v1.0

How to Use

Tick the controls in place to score the agent deployment.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.