---
title: "AI agent security checklist: 22 checks before you ship · DotsAgent"
description: "A 22-item security checklist for AI agents covering untrusted input, tool credentials, sandboxing, MCP tokens and CI secrets. Progress is saved in your browser."
url: https://dotsagent.io/security/checklist
---

Secure · tool

# Agent security checklist

Work through these checks before an agent touches real data or credentials. Each one links to the defence it puts in place, and you can export your progress as a Markdown file for a review or pull request.

0 of 22 done

Ticks are saved in this browser only.

## Untrusted input

- [ ] **Label untrusted content wherever it enters the agent** Mark web pages, emails, issues, tickets and tool results that outsiders can write. Anything on that list can carry instructions. [Break the lethal trifecta →](https://dotsagent.io/security#lethalTrifecta)

- [ ] **Split agents so none holds all three trifecta legs** If an agent reads untrusted content, take away either its private data or its outbound channel. Where one agent needs all three, use plan-then-execute or a dual-LLM design. [Constrain the agent after untrusted input →](https://dotsagent.io/security#designPatterns)

- [ ] **Review and pin the descriptions of every connected tool** Tool descriptions go straight into the model's context. Read them before connecting a server, and hash them so a later change gets flagged. [Vet skills, plugins and MCP servers →](https://dotsagent.io/security#supplyChainVetting)

- [ ] **Escape model output before rendering or executing it** Block auto-loading of external images and links in rendered output and set a strict CSP. Never pass raw output to a shell, SQL query or eval. [Treat model output as untrusted →](https://dotsagent.io/security#outputHandling)

## Tools and credentials

- [ ] **Start every tool connection read-only** Grant write, delete or send rights only to the specific tools that need them, and only for the task at hand. [Use least-privilege credentials →](https://dotsagent.io/security#leastPrivilege)

- [ ] **Scope each token to one project and minimal permissions** No admin or service_role keys for agents. Short-lived, project-scoped tokens keep a leak as small as possible. [Use least-privilege credentials →](https://dotsagent.io/security#leastPrivilege)

- [ ] **Require human approval for writes, deletes and sends** Show the full tool arguments in the approval prompt and fail closed if nobody responds. In OpenClaw, set tools.exec.ask to always. [Require approval for consequential actions →](https://dotsagent.io/security#humanApproval)

- [ ] **Pin exact versions of skills, plugins and MCP servers** Review the diff before every update and check scanner verdicts from VirusTotal or ClawHub audits. In OpenClaw, set security.installPolicy. [Vet skills, plugins and MCP servers →](https://dotsagent.io/security#supplyChainVetting)

- [ ] **Allow outbound traffic only to hosts each tool needs** Deny egress for agents and MCP servers by default. Keep multi-tenant hosts, where anyone can publish content, off every auto-approved list. [Restrict outbound network access →](https://dotsagent.io/security#egressControl)

## Runtime and network

- [ ] **Run code and shell tools in a sandbox** Use a container or VM with no credentials and only the workspace mounted. In OpenClaw, turn sandboxing on, set tools.exec.security to deny or allowlist and keep elevated mode off. [Sandbox code and tool execution →](https://dotsagent.io/security#sandboxing)

- [ ] **Bind gateways and dashboards to loopback only** Reach them remotely through an SSH tunnel or Tailscale Serve and use a token of at least 24 characters. Run openclaw security audit --deep to confirm. [Keep control planes off the internet →](https://dotsagent.io/security#noPublicControlPlane)

- [ ] **Limit who can message the agent** Use DM pairing or an allowlist and require a mention in group chats. Anyone who can message the agent can try to instruct it. [Control who can message the agent →](https://dotsagent.io/security#inboundAccessControl)

- [ ] **Give each user or sender a separate session** Different people should never share one conversation context. In OpenClaw, set session.dmScope to per-channel-peer. [Isolate MCP sessions and tenants →](https://dotsagent.io/security#sessionIsolation)

## MCP servers and clients

- [ ] **Reject MCP tokens that were not issued for your server** Check the audience of every access token, and have clients send RFC 8707 resource indicators so each token is bound to one server. [Validate MCP token audience →](https://dotsagent.io/security#mcpTokenAudience)

- [ ] **Never pass client tokens through to upstream APIs** Obtain separate tokens for upstream calls. If your server proxies to third parties, collect consent from each client to avoid a confused deputy. [Validate MCP token audience →](https://dotsagent.io/security#mcpTokenAudience)

- [ ] **Keep MCP SDKs and tools on patched versions** At minimum: TypeScript SDK 1.26.0, Python SDK 1.27.2, mcp-remote 0.1.16 and MCP Inspector 0.14.1. Create one server and transport per session. [Isolate MCP sessions and tenants →](https://dotsagent.io/security#sessionIsolation)

## CI and code review

- [ ] **Give no secrets to CI agents that outsiders can trigger** Agent jobs that run on pull requests, issues or comments from outsiders get a read-only token and no repository secrets. [Keep secrets out of untrusted CI runs →](https://dotsagent.io/security#ciSecretIsolation)

- [ ] **Treat pull request and issue text as hostile** Titles, descriptions, comments and diffs from outsiders can carry instructions. Require maintainer approval before any job with secrets runs on them. [Keep secrets out of untrusted CI runs →](https://dotsagent.io/security#ciSecretIsolation)

## Operations

- [ ] **Log every tool call with its arguments and result** Keep the log where the agent cannot edit it. You need it to reconstruct an incident and to spot unusual calls.

- [ ] **Keep a fast way to stop agents and revoke their tokens** Know how to halt every running agent and revoke its credentials within minutes. Rehearse it before you need it.

- [ ] **Test your agents against prompt injection before release** Plant instructions in the content your agent reads, such as issues, emails and web pages, and confirm no consequential action follows. Repeat after each change to tools or prompts.

- [ ] **Verify agent signatures before trusting agent traffic** Check Web Bot Auth signatures against the operator's key directory to identify an agent. Authorise what it may do separately, because a signature identifies the operator, not the user. [Verify agent signatures, then authorise →](https://dotsagent.io/security#verifyAgentSignatures)

## Export as Markdown

`SECURITY-CHECKLIST.md`

```
## Untrusted input
- [ ] Label untrusted content wherever it enters the agent
- [ ] Split agents so none holds all three trifecta legs
- [ ] Review and pin the descriptions of every connected tool
- [ ] Escape model output before rendering or executing it

## Tools and credentials
- [ ] Start every tool connection read-only
- [ ] Scope each token to one project and minimal permissions
- [ ] Require human approval for writes, deletes and sends
- [ ] Pin exact versions of skills, plugins and MCP servers
- [ ] Allow outbound traffic only to hosts each tool needs

## Runtime and network
- [ ] Run code and shell tools in a sandbox
- [ ] Bind gateways and dashboards to loopback only
- [ ] Limit who can message the agent
- [ ] Give each user or sender a separate session

## MCP servers and clients
- [ ] Reject MCP tokens that were not issued for your server
- [ ] Never pass client tokens through to upstream APIs
- [ ] Keep MCP SDKs and tools on patched versions

## CI and code review
- [ ] Give no secrets to CI agents that outsiders can trigger
- [ ] Treat pull request and issue text as hostile

## Operations
- [ ] Log every tool call with its arguments and result
- [ ] Keep a fast way to stop agents and revoke their tokens
- [ ] Test your agents against prompt injection before release
- [ ] Verify agent signatures before trusting agent traffic
```

Independent reference for people who build AI agents. Not affiliated with any vendor named here.

© 2026 DotsAgent · Facts checked October 1, 2026
