Threats and control boundaries
Threat scenarios for agent skills, tools and connected services.
INDEPENDENT SECURITY RESOURCE
A working guide to the permissions, provenance and runtime controls behind AI agent skills, MCP servers and connected tools.
Open the reviewA proposed control boundary
Conceptual architecture. This website does not inspect, block or execute your agent tools.
Review a skillA useful starting point
Instructions, scripts and connected services can turn a language model’s output into action. Review the full capability, the data it can reach, and the systems that enforce its limits.
Read the field guideInside the guide
Threat scenarios for agent skills, tools and connected services.
A reference workflow for enforcing agent capability policy.
A maintenance and incident response worksheet.