← Checklists

Founder playbook

AI Agent Security Checklist

A practical security checklist for agents that can call tools or take external actions.

1

Give the agent only required tools

2

Use scoped and short-lived credentials

3

Separate trusted instructions from external content

4

Require approval for high-impact actions

5

Sandbox code execution

6

Keep secrets out of prompts and logs

7

Audit tool calls

8

Apply rate, cost, and action limits

9

Give the agent an explicit identity

10

Test failure and abuse paths

Use the checklist as a decision tool, not a ritual.

Skip items that do not apply, document assumptions, and measure the outcome of the work you actually do.