Agent Security Review
An audit of what your AI agents can access — and what happens if that access is misused.
The risk isn't that someone hacks your AI. It's that your AI already has more access than anyone remembers granting it — and a single email, document, or web page it reads can make it act on that access without your knowledge. We map the access, test the manipulation, and hand you the fix list.
Permission creep is the quiet risk.
AI agents don't get access all at once. The email assistant gets send rights "just for drafts". The CRM bot gets write access "to save time". The bookkeeping automation gets the payment portal login "temporarily". Six months later, no one can list what the AI in the business can actually do — and there's usually no log of what it has done.
Meanwhile, agents follow instructions found in the content they process, not just the ones you give them. An email your assistant summarises, a PDF your intake bot reads, a web page your research agent visits — each is a channel through which someone else can tell your AI what to do. That combination — broad access, no log, outside influence — is the exposure this review measures.
Unlisted access
Most businesses cannot produce a list of what their AI tools can read, send, or change. The audit starts by building one.
No audit trail
When an agent sends the wrong email or edits the wrong record, most setups have no way to know it happened.
Outside influence
Agents act on instructions inside the content they read. Attackers know this. Most deployments were never tested for it.
What the review covers.
Three modules — map the access, test the manipulation, trace the data.
Access & Permission Mapping
A full inventory of what your AI can already touch — usually more than anyone remembers granting.
- Every agent, bot, custom GPT and automation in the business — including the ones IT doesn't know about
- What each one can read, send, or change: inboxes, CRM records, documents, payment rails
- Where access exceeds what the task requires — the CRM bot that started read-only and now sends email
- Who can grant an agent new access, and whether anyone reviews it
Injection & Exploitation Testing
We test whether your agents can be manipulated by the content they read — not by a person giving commands.
- Indirect prompt injection tests — instructions hidden in an email, document or web page your agent processes
- Whether a manipulated agent can act on its access: send mail, alter records, leak data
- Spend-control checks — what stops an agent loop from burning your AI API budget
- Reproducible results — every successful manipulation is documented so you can see it yourself
Data Handling & Vendor Exposure
Where client data enters AI systems — through your staff, your tools, and your vendors.
- Staff usage review — client data pasted into public chatbots is a confidentiality breach, not a convenience
- Whether agent actions are logged anywhere — most businesses can't answer "what did the bot do last Tuesday?"
- Vendor AI features — what the AI inside your existing software can see, and what it does with it
- Data residency and retention of AI tool inputs, mapped against your client confidentiality obligations
The Agent Access & Exposure Report
Written for the person accountable for the business, not the person who configured the bot. Suitable for a board, an investor, or a client asking hard questions about your AI use.
- Full inventory of agents, bots and AI-enabled tools
- Risk-graded permission map (critical / high / medium)
- Reproducible injection test results — see the manipulation yourself
- Data-leakage findings, including staff chatbot usage
- Vendor AI-feature exposure list
- Prioritised remediation roadmap with owners and one-page executive summary
Choose your review scope.
Active StackGuard clients add this as a module from ₹45,000 — discovery is already done, so you don't pay for it twice.
A simple rule for whether you need this: if your AI tools only draft and research, StackGuard's audit covers you. If any AI tool can send email, update a record, or move money on its own — you need the Agent Security Review.
Single-Agent Review
One agent or bot, fully tested
Ideal for: One agent doing real work
- Permission map for one agent (e.g. your email assistant or support bot)
- Injection and exploitation testing
- Documented findings with reproduction steps
- Prioritised remediation list
Multi-Agent Review
Every agent and AI-enabled tool
Ideal for: Businesses running multiple AI tools
- All agents, bots, custom GPTs and automations in scope
- Full Access & Permission Map across the business
- Injection testing on every agent with real access
- Staff data-handling and vendor AI review
- Agent Access & Exposure Report + leadership debrief
Agent Governance Review
Multi-Agent scope + controls built
Ideal for: Agents touching client data or money
- Everything in Multi-Agent Review
- Audit-trail design — know what every agent did, and when
- Spend-cap policy for AI API usage
- Staff data-handling controls and training outline
- Quarterly re-review for 12 months
How the review works.
Kickoff Call
We inventory your agents, bots and AI-enabled tools, and agree the testing scope in writing. 30–45 minutes.
Testing
Permission mapping, then controlled injection and exploitation testing against the agreed scope. Nothing destructive, everything logged.
Report
The Agent Access & Exposure Report — risk-graded permission map, reproducible findings, remediation roadmap.
Debrief
We walk your leadership team through what we found and what to fix first, in plain language.
A typical Agent Security Review runs 7–10 business days from kickoff to final report. All testing is scoped and agreed in writing before it begins.
Not sure your basics are covered?
The Agent Security Review assumes your general security posture is known. If it isn't, start with StackGuard — the full AI-era security audit — and add this review as a module. Combined engagements share discovery, so the second audit costs less.
Find out what your AI can actually do.
In 7–10 business days you'll have the full permission map, tested manipulation findings, and a fix list in priority order.
Book an Agent Security Review →