AI Agent Permission Auditor
Audit what an autonomous agent can actually do, covering tool scope, identity, the boundary between untrusted content and instructions, and the controls that make agent actions reviewable.
Last reviewed by the Radiatus Cloud team
Securing AI in production?
We build guardrails, governance & compliance for AI systems.
An agent is its tools, not its prompt
The security properties of an agent deployment are determined almost entirely by what the tools can do and what credentials they carry. A system prompt instructing the model not to delete anything is a request; a credential without delete permission is a control. This distinction gets lost because prompts are visible and easy to change while permissions live in a different system, so the review that happens is a review of the prompt, which is the half that cannot enforce anything.
Prompt injection is a structural problem, not a filtering one
When retrieved documents, emails, web pages or tool output are concatenated into the same context as the operator's instructions, the model has no reliable way to distinguish them, because there is no channel separating them. Every mitigation applied at the instruction level, telling the model to ignore instructions in retrieved content, is asking the model to solve a problem the architecture created. The durable defences are structural: keep untrusted content out of the instruction channel, validate what comes back before it reaches a tool, and scope the tools so that a successful injection reaches something harmless.
Borrowed identity destroys attribution
Agents are commonly deployed using an existing service account or, worse, a named employee's credentials. Every action then appears in every downstream log as that principal, so an investigation cannot separate what a person did from what an agent did on their behalf, and revoking the agent's access revokes the person's. Giving the agent its own identity costs almost nothing at deployment and is close to impossible to retrofit after an incident.
Related tools
- AI Prompt Leakage Analyzer — Paste a system prompt and a hostile user input to see whether the prompt holds secrets and whether the input carries injection patterns. Local, instant.
- LLM Data Exposure Checker — Check if text contains data likely to be memorized or exposed by LLMs.
- AI Usage Policy Generator — Generate an acceptable use policy for AI tools in your company.
- Model Hallucination Estimator — Estimate risk of hallucinations based on task type and temperature.
Frequently Asked Questions
Why does the system prompt not count as a control?
Because it is a request rather than an enforcement point. A model can be persuaded to disregard it, whereas a credential without delete permission cannot delete regardless of what the model decides.
Can prompt injection be filtered?
Not reliably. It is a structural problem created by merging untrusted content into the instruction channel, and instruction-level mitigations ask the model to solve a problem the architecture created. The durable defences are separation, output validation and tool scoping.
Why should an agent have its own identity?
Because an agent using a person’s credentials is indistinguishable from that person in every log, so attribution fails exactly when it matters, and revoking the agent removes the person’s access too.
Does human approval solve the problem?
Only if the reviewer sees what will actually happen. A confirmation step that displays the model’s own description of its action approves the description rather than the action.
Is unrestricted network access a real risk?
Yes. Unrestricted fetch is an exfiltration channel, because content the agent has read can be encoded into a URL it is persuaded to request. An allowlist closes it without removing the capability.
Privacy & Security
Everything runs in your browser; nothing is uploaded.
How to Use
Tick the controls in place to score the agent deployment.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
AI Prompt Leakage Analyzer
AI SecurityPaste a system prompt and a hostile user input to see whether the prompt holds secrets and whether the input carries injection patterns. Local, instant.
LLM Data Exposure Checker
AI SecurityCheck if text contains data likely to be memorized or exposed by LLMs.
AI Usage Policy Generator
AI SecurityGenerate an acceptable use policy for AI tools in your company.