Permission is a graph.
Map the farthest edge.
Describe one proposed agent tool without pasting code or credentials. The local review exposes maximum plausible side effects and missing deterministic controls before anyone grants access; it never claims the implementation is secure.
One-tool authorization boundary review
Plausible side effects to bound
Controls or evidence still required
Points only prioritize review; they are not a vulnerability score or approval. The tool cannot inspect actual code, permissions, identity, downstream calls or logs.
Security boundary: do not paste source code, prompts, tokens, credentials, private hostnames, customer data or architecture details. Treat every selection as an unverified declaration. Deterministic policy, parameter validation, least privilege, logging, tested stop controls and authorized human review must exist outside the model.
$11 Pre-Authorization Review Pack
Generate a reusable Markdown decision record with declared authorization surface, maximum-impact questions, explicit deny rules, scoped approval, failure-containment tests and rollback evidence. It remains a design artifact, not a scan or certification.
- Identity, operation, target and downstream-reach boundary
- Fresh-approval and explicit-deny decision record
- Prompt-injection, target-cap, retry and stale-approval tests
- Kill-switch, partial-effect and rollback drill evidence
Current primary controls and visible substitutes
PMF preflight 67/100 · 21 days + 150 qualified visits + paid evidence