Run the audit

Paste the agent's system prompt, tool/function definitions, permission or policy configuration, orchestration code, or deployment notes below. The engine evaluates capability, authority, controls, and residual exposure across the agent's operating boundary.

Runs entirely in your browser. Nothing you paste is sent anywhere.

0 characters

Agent exposure profile

Findings

Assessment logic: capability evidence is evaluated separately from control evidence. A stated control reduces residual exposure but does not erase an underlying capability. An unstated control is reported as NOT STATED rather than assumed safe.
This is a pattern-based reading of the text you pasted, not a runtime security audit. It cannot verify infrastructure-enforced permissions, actual tool behavior, production isolation, secrets handling, identity controls, or anything left unstated. Findings describe textual exposure evidence and should be validated against the deployed system.