Review the control plane
Map human, service and agent identities, delegated permissions, tools, data, memory and external side effects.
Field guide / defensive assurance
A useful review is not a scanner dump. It is a bounded answer to whether an agent can act with more authority, context or access than the system owner intended — and what evidence proves the answer.
Map human, service and agent identities, delegated permissions, tools, data, memory and external side effects.
Use the review before launch or before adding a tool, persistent memory, sensitive data, payment capability or a new dependency.
Inspect the MCP server card, tool schemas, authentication, validation, side effects, egress and human-approval boundaries — with written authorization.
Can every human, service and agent action be attributed to an identity that can be independently revoked?
Are tools, resources, spend and side effects least-privileged at action time rather than trusted by prompt or role alone?
Can prompt injection, retrieval results or memory writes cross a trust boundary and become durable instructions?
Are egress, secrets, uploads, webhooks and third-party calls explicit, validated and observable?
Do timeouts, retries, malformed inputs and partial results fail closed without duplicating an irreversible action?
Does each finding have reproducible evidence, an owner, a remediation path and a verification procedure?
The output is a decision-grade record: scope and limitations, a trust-boundary model, ranked abuse cases, evidence-backed findings, remediation ownership and one repeatable verification path.
Delx Security uses public frameworks as a vocabulary — including NIST CSF, NIST AI RMF, OWASP Agentic Top 10, OWASP ASVS and MITRE ATLAS — not as a substitute for observing the actual system.
Start with the five-minute readiness checklist → or compare bounded services →
It is a bounded assessment of an agent's identities, authority, tools, context, data flows and recovery controls. The review connects credible abuse paths to evidence, remediation and a repeatable verification step.
It can. An authorized review can inspect MCP server discovery, tool schemas, authentication, input validation, side effects, egress and approval boundaries. The exact transport and targets must be written into scope.
Before production launch, before adding tools or memory, before granting access to sensitive data or spend, and after a material architecture or dependency change.
No. Delx Security reports the tested scope, evidence, limitations, findings and residual risk. It does not issue a whole-system certification or guarantee future security.