← Checklists
Founder playbook
AI Agent Security Checklist
A practical security checklist for agents that can call tools or take external actions.
1
Give the agent only required tools
2
Use scoped and short-lived credentials
3
Separate trusted instructions from external content
4
Require approval for high-impact actions
5
Sandbox code execution
6
Keep secrets out of prompts and logs
7
Audit tool calls
8
Apply rate, cost, and action limits
9
Give the agent an explicit identity
10
Test failure and abuse paths
Use the checklist as a decision tool, not a ritual.
Skip items that do not apply, document assumptions, and measure the outcome of the work you actually do.