Nine questions · before you deploy

What controls does this agent actually need?

Describe one agent. This returns the risk tier, the OWASP agentic risks it exposes you to, the controls that become mandatory, and the framework provisions that attach — as a record you can put straight into a change ticket or an agent register.

Nothing leaves your browser. No network calls, no storage, no analytics. Agent names describe your internal architecture, so they stay on your device.
Indicative tier0/9AWAITING INPUT
ACTAction scope · 1 of 9

What is this agent able to do?

Take the highest capability it holds, not the one it usually uses.

INPUntrusted input · 2 of 9

What content does it ingest?

Anything it reads can carry instructions. This is the indirect prompt injection surface.

REVReversibility · 3 of 9

Can its actions be undone?

Judge the worst action it can take, not the typical one.

DATData classification · 4 of 9

What data can it reach?

Highest classification it can access, including through its tools.

CRDCredential posture · 5 of 9

How does it authenticate?

This determines whether you can revoke it independently.

HUMHuman oversight · 6 of 9

Where is the human in the loop?

Approval that exists on paper but is never exercised counts as post-hoc.

TOOTool composition · 7 of 9

How does it acquire its tools?

Dynamic discovery means the tool set at runtime is not the set you reviewed.

DELDelegation · 8 of 9

Does it work with other agents?

Delegation is where attribution to a human principal usually breaks.

RCHReachability · 9 of 9

Who can invoke it?

Exposure multiplies every other factor.

This is triage. Nine questions cannot capture a real architecture — the output tells you what to examine properly and which controls to require, not that an agent is safe.

Aligned to the OWASP Top 10 for Agentic Applications 2026. To score a discovered vulnerability rather than determine controls before deployment, use the OWASP AI Vulnerability Scoring System.

Provided for readiness planning. Not a compliance determination, and not legal advice. Mappings current as at July 2026.

© 2026 Aseem Mohan · Organisational assessment · Privacy notice