assess_agent_security
Assess an AI agent's security posture based on the OWASP Agentic AI Top 10 framework. Supply details on key controls like input validation, output filtering, and privilege management to get a structured risk analysis.
Instructions
Full OWASP Agentic AI Top 10 security assessment.
Behavior: This tool is read-only and stateless — it produces analysis output without modifying any external systems, databases, or files. Safe to call repeatedly with identical inputs (idempotent). Free tier: 10/day rate limit. Pro tier: unlimited. No authentication required for basic usage.
When to use: Use this tool when you need structured analysis or classification of inputs against established frameworks or standards.
When NOT to use: Not suitable for real-time production decision-making without human review of results.
Args: agent_name (str): The agent name to analyze or process. has_input_validation (bool): The has input validation to analyze or process. has_output_filtering (bool): The has output filtering to analyze or process. has_tool_allowlist (bool): The has tool allowlist to analyze or process. has_least_privilege (bool): The has least privilege to analyze or process. has_context_isolation (bool): The has context isolation to analyze or process. has_action_logging (bool): The has action logging to analyze or process. has_auth_between_agents (bool): The has auth between agents to analyze or process. has_resource_limits (bool): The has resource limits to analyze or process. has_dependency_scanning (bool): The has dependency scanning to analyze or process. has_alignment_testing (bool): The has alignment testing to analyze or process. api_key (str): The api key to analyze or process.
Behavioral Transparency: - Side Effects: This tool is read-only and produces no side effects. It does not modify any external state, databases, or files. All output is computed in-memory and returned directly to the caller. - Authentication: No authentication required for basic usage. Pro/Enterprise tiers require a valid MEOK API key passed via the MEOK_API_KEY environment variable. - Rate Limits: Free tier: 10 calls/day. Pro tier: unlimited. Rate limit headers are included in responses (X-RateLimit-Remaining, X-RateLimit-Reset). - Error Handling: Returns structured error objects with 'error' key on failure. Never raises unhandled exceptions. Invalid inputs return descriptive validation errors. - Idempotency: Fully idempotent — calling with the same inputs always produces the same output. Safe to retry on timeout or transient failure. - Data Privacy: No input data is stored, logged, or transmitted to external services. All processing happens locally within the MCP server process.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| agent_name | Yes | ||
| has_input_validation | No | ||
| has_output_filtering | No | ||
| has_tool_allowlist | No | ||
| has_least_privilege | No | ||
| has_context_isolation | No | ||
| has_action_logging | No | ||
| has_auth_between_agents | No | ||
| has_resource_limits | No | ||
| has_dependency_scanning | No | ||
| has_alignment_testing | No | ||
| caller | No | ||
| api_key | No |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |