Free defensive tool
AI Agent Security Checklist
Turn agentic-AI research into an evidence-ready review of authority, untrusted input, delegation, memory, approvals, logging, and recovery.
Tool guidance
How to use this tool
The checklist runs entirely in your browser and does not submit your answers.
How to use it
Answer each control with yes, partly, no, or unknown.
Review the category scores and critical authority gaps.
Copy the defensive action plan for an engineering or security review.
Validate high-impact controls with implementation evidence before deployment.
What results mean
The score is transparent and comes only from your answers.
Unknown and unanswered controls lower confidence.
This tool does not execute commands, inspect prompts, or connect to an AI system.
What to do next
Move high-impact actions behind explicit approval.
Separate untrusted content from operator instructions.
Request a manual architecture review for production agents.
Research-informed, not research-overstated
The UIUC studies showed that planning, documents, task-specific agents, and tool access changed performance inside controlled vulnerability benchmarks. This checklist translates that observation into defensive questions. It does not reproduce the offensive agents, prompts, or exploit workflows.
For current operational context, NIST describes agent risk in terms of tool permissions and trusted or untrusted environments. Read the NIST tool-access taxonomy and the two source-paper summaries in the CheckLink research hub.