Vince CorvettiDarkMode SecurityLet’s talk
Menu

Agent Security Advisory

Know what your AI agents can do—and where authority accumulates.

I examine the full chain behind an agent’s actions: instructions, workflows, tools, identities, credentials, data, runtime controls, and human decisions.

Control behavior is described as tested only when validation is explicitly authorized, scoped, and recorded.

What I assess

Follow the authority, not just the agent.

Scope follows the workflow, deployment stage, intended decision, and risk. Open a domain for the detail behind it.

Agents & architecture

Workflows, orchestrators, runtimes, trust boundaries, and delegated paths.

Skills & instructions

Source, ownership, triggers, dependencies, activation boundaries, and unintended-use paths.

Tools & connectors

APIs, MCP, plugins, allowed operations, approvals, destinations, logging, and failure behavior.

Identity & credentials

Scopes, tokens, service accounts, inheritance, least privilege, rotation, and revocation.

Data & memory

Sensitive flows, retrieval, provenance, retention, poisoning, and exfiltration paths.

Runtime & response

Sandboxing, egress, telemetry, isolation, evidence preservation, rollback, and recovery.

Supply chain & change

Provenance, versioning, integrity, update approval, lifecycle, and decommissioning.

Human & multi-agent controls

Delegation, task provenance, approvals, separation of duties, escalation, and oversight.

Skills are a first-class assessment object. Their source, triggers, scripts, dependencies, tool access, stop conditions, and unintended-use paths can shape the authority of the whole system.

Skills, tooling, and representative abuse paths

Review depth may include provenance, permissions, composition with connected tools and identities, change control, containment, recovery, and rollback.

Representative paths: indirect prompt injection, goal hijacking, tool misuse, privilege abuse, memory poisoning, insecure delegation, supply-chain compromise, and cascading failures.

Evidence states

Finding a control is not the same as proving it works.

Discovery

What appears to exist

Architecture, configuration, documentation, and evidence review show the current picture—and label what remains uncertain.

Authorized validation

How a selected control behaved

Defined scenarios, recorded observations, limits, and residual uncertainty support a narrower testing claim.

How the work moves

Connected disciplines. One traceable decision.

Methods are selected for the agreed question. Discovery never silently expands into testing or implementation.

  1. 01

    Discover and map

    Make the scoped capability, dependency, privilege, and ownership chain visible.

  2. 02

    Threat-model and test

    Define representative failure modes and test only within explicit authorization.

  3. 03

    Design and harden

    Shape least privilege, approval gates, reversible actions, logging, and containment.

  4. 04

    Govern and operationalize

    Set roles, risk tiers, deployment gates, exceptions, and change controls.

  5. 05

    Monitor and respond

    Define telemetry, isolation, revocation, evidence preservation, rollback, and recovery.

  6. 06

    Assure and communicate

    Translate evidence into findings, remediation, residual-risk decisions, and reporting.

Start with the decision

What must be known before this agent moves forward?

A short, non-sensitive description of the workflow, deployment stage, decision, and timing is enough.

Defined workflowDecision ownerAgreed boundary
Start an agent-security conversation Do not include credentials, sensitive data, production access details, or regulated information.