Secure · tool
Agent security checklist
Work through these checks before an agent touches real data or credentials. Each one links to the defence it puts in place, and you can export your progress as a Markdown file for a review or pull request.
Untrusted input
Tools and credentials
Runtime and network
MCP servers and clients
CI and code review
Operations
Export as Markdown
## Untrusted input
- [ ] Label untrusted content wherever it enters the agent
- [ ] Split agents so none holds all three trifecta legs
- [ ] Review and pin the descriptions of every connected tool
- [ ] Escape model output before rendering or executing it
## Tools and credentials
- [ ] Start every tool connection read-only
- [ ] Scope each token to one project and minimal permissions
- [ ] Require human approval for writes, deletes and sends
- [ ] Pin exact versions of skills, plugins and MCP servers
- [ ] Allow outbound traffic only to hosts each tool needs
## Runtime and network
- [ ] Run code and shell tools in a sandbox
- [ ] Bind gateways and dashboards to loopback only
- [ ] Limit who can message the agent
- [ ] Give each user or sender a separate session
## MCP servers and clients
- [ ] Reject MCP tokens that were not issued for your server
- [ ] Never pass client tokens through to upstream APIs
- [ ] Keep MCP SDKs and tools on patched versions
## CI and code review
- [ ] Give no secrets to CI agents that outsiders can trigger
- [ ] Treat pull request and issue text as hostile
## Operations
- [ ] Log every tool call with its arguments and result
- [ ] Keep a fast way to stop agents and revoke their tokens
- [ ] Test your agents against prompt injection before release
- [ ] Verify agent signatures before trusting agent traffic