๐Ÿง  AI agent permission reviewer

AI agents are non-human identities with tools. Paste what yours can do and see how far a single injected instruction could reach.

๐Ÿ”’ Reviewed in your browser. Your configuration and any secrets in it never leave this page, and secret values are never shown back.

Secret values you paste are never shown back or sent anywhere; the review only notes that a secret is present.

Why this matters

An agent connected to a shell, a mailbox and the web holds more power than most service accounts, and it takes instructions from whatever text it reads. Prompt injection turns every document, email and web page into a possible operator.

The fix is identity work: scope each tool, keep credentials out of config files, require approval for actions that change or send data, and never give one agent private data, untrusted content and an outbound channel at the same time.