Auditing AI Agent Permissions

Audit what an AI agent is actually allowed to do versus what its task needs. Covers excessive agency (tools, scopes, and autonomy beyond the job), missing human-in-the-loop gates on irreversible actions, over-broad credentials and their blast radius, sandbox and code-interpreter escape, unfiltered egress, and unbounded resource or spend (denial-of-wallet). Use when granting an agent a tool or scope, reviewing an agent's permission posture, or deciding which actions need approval. The model's restraint is not a control; permissions are.

UnboundCompute afdf505 6.4 KB Updated

File contents

UnboundCompute/security-agent-skills/tree/main/skills/auditing-ai-agent-permissions commit afdf5053e5

Frequently asked questions

npx skillmds@latest add unboundcompute/auditing-ai-agent-permissions