← Inspection rules
SEC-011 / v1.1.0 / 2026-10-02
Inspect AI-agent destinations and execution privileges
Editorial inspection guidance. Start with read-only permissions; fixes, credential revocation, and production changes follow the owner’s authorization.
Applicability
Applies to agents and evaluation environments with code execution or tool connectivity.
Where to look first
- Agent network settings, package proxies, tool connections such as MCP, and service accounts.
- Boundaries among evaluation, CI, and production, plus connection and privilege-change records.
Inspection steps
- Compare prompt restrictions with actual controls; inspect settings and existing tests for proxy routes to external or production systems.
- Inspect per-tool read, write, and publish authority for unapproved connections, shared keys, or excessive privileges without retrieving secret values.
- Verify human approval requirements, execution logs, and stop mechanisms; do not accept model self-reports as evidence.
Remediation direction
- Separate service accounts by purpose and restrict destinations and operations; enforce networking outside the model.
- Separate production connectivity and publishing authority from evaluation; approve and record exceptions and propose authorized containment and revocation.
Evidence required for completion
- Destination and privilege inventory and configuration review tied to the environment revision.
- Authorized boundary-test records, approval history, execution logs, and verified stop mechanisms.
Limits and unverified scope
- Settings alone do not establish effective isolation; missing tests or runtime access remain unverified.
- Using this catalog does not authorize external communication, credential revocation, or privilege changes.