Agentic Risk Assessment

Assess and bound the security risk of an agentic AI deployment before approving it. Use when a team asks to connect an agent to internal systems, when reviewing a personal agent harness or an autonomous service agent, when writing an agent security review process, or when deciding which controls a vendor must demonstrate. Applies a four-question risk assessment (untrusted content, actions and identity, blast radius, observability), places the deployment on the identity spectrum from service account to human credential, and checks it against seven deployment controls covering identity, connector allowlists, per-action approval, sandboxed execution, egress allowlisting, telemetry, and an off switch.

uygnoey Updated

File contents

uygnoey/skills-from-claude-blog/tree/main/2026.07.17_ciso-guide-to-agentic-ai/skills/agentic-risk-assessment commit d5aa39203b

Frequently asked questions

npx skillmds@latest add uygnoey/agentic-risk-assessment