Discovery
What appears to exist
Architecture, configuration, documentation, and evidence review show the current picture—and label what remains uncertain.
Agent Security Advisory
I examine the full chain behind an agent’s actions: instructions, workflows, tools, identities, credentials, data, runtime controls, and human decisions.
Control behavior is described as tested only when validation is explicitly authorized, scoped, and recorded.
What I assess
Scope follows the workflow, deployment stage, intended decision, and risk. Open a domain for the detail behind it.
Workflows, orchestrators, runtimes, trust boundaries, and delegated paths.
Source, ownership, triggers, dependencies, activation boundaries, and unintended-use paths.
APIs, MCP, plugins, allowed operations, approvals, destinations, logging, and failure behavior.
Scopes, tokens, service accounts, inheritance, least privilege, rotation, and revocation.
Sensitive flows, retrieval, provenance, retention, poisoning, and exfiltration paths.
Sandboxing, egress, telemetry, isolation, evidence preservation, rollback, and recovery.
Provenance, versioning, integrity, update approval, lifecycle, and decommissioning.
Delegation, task provenance, approvals, separation of duties, escalation, and oversight.
Skills are a first-class assessment object. Their source, triggers, scripts, dependencies, tool access, stop conditions, and unintended-use paths can shape the authority of the whole system.
Review depth may include provenance, permissions, composition with connected tools and identities, change control, containment, recovery, and rollback.
Representative paths: indirect prompt injection, goal hijacking, tool misuse, privilege abuse, memory poisoning, insecure delegation, supply-chain compromise, and cascading failures.
Evidence states
Discovery
Architecture, configuration, documentation, and evidence review show the current picture—and label what remains uncertain.
Authorized validation
Defined scenarios, recorded observations, limits, and residual uncertainty support a narrower testing claim.
How the work moves
Methods are selected for the agreed question. Discovery never silently expands into testing or implementation.
Make the scoped capability, dependency, privilege, and ownership chain visible.
Define representative failure modes and test only within explicit authorization.
Shape least privilege, approval gates, reversible actions, logging, and containment.
Set roles, risk tiers, deployment gates, exceptions, and change controls.
Define telemetry, isolation, revocation, evidence preservation, rollback, and recovery.
Translate evidence into findings, remediation, residual-risk decisions, and reporting.
Start with the decision
A short, non-sensitive description of the workflow, deployment stage, decision, and timing is enough.