← Inspection rules

SEC-011 / v1.1.0 / 2026-10-02

Inspect AI-agent destinations and execution privileges

Editorial inspection guidance. Start with read-only permissions; fixes, credential revocation, and production changes follow the owner’s authorization.

Applicability

Applies to agents and evaluation environments with code execution or tool connectivity.

Where to look first

  • Agent network settings, package proxies, tool connections such as MCP, and service accounts.
  • Boundaries among evaluation, CI, and production, plus connection and privilege-change records.

Inspection steps

  1. Compare prompt restrictions with actual controls; inspect settings and existing tests for proxy routes to external or production systems.
  2. Inspect per-tool read, write, and publish authority for unapproved connections, shared keys, or excessive privileges without retrieving secret values.
  3. Verify human approval requirements, execution logs, and stop mechanisms; do not accept model self-reports as evidence.

Remediation direction

  • Separate service accounts by purpose and restrict destinations and operations; enforce networking outside the model.
  • Separate production connectivity and publishing authority from evaluation; approve and record exceptions and propose authorized containment and revocation.

Evidence required for completion

  • Destination and privilege inventory and configuration review tied to the environment revision.
  • Authorized boundary-test records, approval history, execution logs, and verified stop mechanisms.

Limits and unverified scope

  • Settings alone do not establish effective isolation; missing tests or runtime access remain unverified.
  • Using this catalog does not authorize external communication, credential revocation, or privilege changes.

Additional references