Free practical resource

AI Agent Security Readiness Checklist

A practical AI agent security checklist for tool permissions, prompt injection, sensitive data, integrations, human oversight and incident readiness.

Before an assistant or autonomous agent can read business data or take actions, document what it can reach, which instructions it should trust and who can stop it. Use this checklist for a single workflow; repeat it for additional agents and connected systems.

For each question, mark Yes / No / Unknown / Not applicable. Treat No and Unknown as follow-up work; they are not automatic proof of a vulnerability. A team can use this resource independently without requesting a consulting engagement.

Print or save it as PDF using your browser's Print command (Ctrl+P). The page has a printer-friendly layout. Do not put secrets or private customer information into the worksheet.

1. Workflow and inventory

  • ☐ Can we name the agent's purpose, owner, users and permitted business outcomes?
  • ☐ Do we have a complete list of connected tools, APIs, MCP servers, data stores and external providers?
  • ☐ Have we mapped the inputs, outputs and places where external/untrusted content enters the workflow?
  • ☐ Can we distinguish test, staging and production environments and their credentials?

2. Prompt injection and instruction boundaries

  • ☐ Are external documents, search results, emails, web pages and tool responses treated as data, not trusted instructions?
  • ☐ Are tool invocations and privileged operations authorized independently of the model's text output?
  • ☐ Do we know what happens if retrieved text tells the agent to ignore rules, leak information or call another tool?
  • ☐ Are tool results and generated output validated before being used in downstream code or actions?

Why it matters: A malicious instruction can arrive through otherwise ordinary content. Prompt wording alone is not an adequate authorization boundary.

3. Identity, authorization and least privilege

  • ☐ Does each agent or integration use an identifiable principal with only required scopes and permissions?
  • ☐ Are read-only actions separated from create, update, send, purchase, delete and administrative actions?
  • ☐ Does the receiving API enforce user/tenant authorization rather than trusting the agent to decide access?
  • ☐ Are credentials short-lived or rotatable where supported, with secrets kept out of prompts and logs?
  • ☐ Have we explicitly rejected unnecessary wildcard permissions or broad shared service accounts?

4. Sensitive information and third parties

  • ☐ Do we know which personal, confidential or regulated data the workflow can read, retrieve, transmit or store?
  • ☐ Are model-provider and third-party retention, training, region and logging terms understood for this use case?
  • ☐ Do connectors and MCP servers have known owners, trusted origins and reviewed permission requirements?
  • ☐ Are secret values, access tokens and internal-only data prevented from reaching untrusted tools or output channels?
  • ☐ Is there an explicit process to remove a compromised or unwanted integration and revoke its permissions?

5. External actions and human approval

  • ☐ Are high-impact actions (external messages, purchases, deletions, publication or permission changes) identified?
  • ☐ Do consequential actions require a human confirmation showing the target, content and likely effect?
  • ☐ Is approval checked at the point of execution, and can the human reject or change the proposed action?
  • ☐ Can one agent action trigger further actions without fresh authorization? If yes, is that delegation bounded?
  • ☐ Are irreversible actions constrained by limits, allowlists or separation of duties where feasible?

6. Runtime, monitoring and recovery

  • ☐ Can operators identify who initiated a request, which agent acted, which tool ran and the outcome?
  • ☐ Are relevant events logged without copying sensitive prompts, tokens or personal information unnecessarily?
  • ☐ Are there bounded timeouts, retries, token/cost budgets and rate limits for tool and model calls?
  • ☐ Is there a practical way to pause or disable the agent and revoke its access quickly?
  • ☐ Do we have an incident contact, escalation process and plan for investigating an unexpected action?
  • ☐ Have we rehearsed at least one safe failure scenario, using synthetic information and non-production actions?

7. Operational decision

Record the three highest-priority gaps, who owns each one and a target date before connecting the workflow to sensitive systems or allowing consequential autonomous actions.

Priority Gap / missing evidence Owner Action / decision
1
2
3

When to request a deeper review

A focused independent assessment is particularly useful when a workflow has write/delete permissions, access to customer data, third-party connectors, agent-to-agent delegation or external actions and the team cannot show the current controls and decision boundaries.

See the scoped AI Agent Security Readiness Review → or email a short workflow description →.

References and limitations

This checklist is an operational starting point, not an exhaustive test suite, OWASP publication, certification, guarantee or substitute for a specialist penetration test. It draws on:

Last reviewed: October 8, 2026. The original reference publications remain authoritative if terminology or guidance changes.