Before an AI agent gets tool access, review the permissions like production access.
This kit helps teams plan MCP and AI agent workflows with tool permission checks, prompt injection review, rollout planning, risk registers, and incident response boundaries.
Use it when experiments are moving toward real internal tools, customer data, admin actions, or automation workflows.
Preview checklist
Review before rollout:
- what the agent can read
- what it can write
- what secrets it can touch
- which tools need approval
- where logs go
- what happens after prompt injection
- who owns incident response
What is included
- MCP security review prompts
- AI agent ops prompts
- prompt injection threat model
- tool permission matrix
- risk register templates
- incident response workflow
- rollout workflow
- helper scripts
- Cursor rules
- documentation
- license
- manifest
- SHA256 checksums
Built for
- AI platform teams
- security engineers
- automation engineers
- MSP technical teams
- internal IT teams using MCP or agent workflows
Use this when
- an internal AI tool is getting real permissions
- an MCP server exposes tools, files, data, or actions
- teams need a permission matrix before rollout
- security and ops need a human-reviewed incident path
Delivery and usage
- Digital download delivered as a ZIP file.
- Individual license for internal operational use.
- No resale, redistribution, repackaging, or public sharing.
- Review all scripts, prompts, templates, and outputs before use.
Important: This kit is advisory and designed for human-reviewed security and operations workflows. It is not a managed security service, formal compliance certification, penetration test, or guarantee that an AI agent deployment is secure.