A checklist for securing your AI agent setup

$ cat blog/securing-ai-agent-setups.md
✓ AI security
✓ agents
✓ MCP
✓ checklist
8 min read
$ 

Teams are shipping LLM agents faster than they're reviewing them. An agent setup — the agent definitions, skills, memory stores, tool and MCP configurations, and the hooks that wire them together — is code and configuration like anything else, and it carries security weight that a normal code review often misses.

Here's a defensive checklist you can run against a repository today.

Tools and permissions

  • Is every tool necessary? Remove tools the agent doesn't use. Each one is attack surface.
  • Are file and shell tools scoped? A read tool with access to the entire filesystem can read .env, credentials, and infra secrets. Scope it, and explicitly deny credential-bearing paths.
  • Is the permission model allow-list or deny-list? Prefer deny-by-default with an explicit allow-list. Deny-lists of dangerous patterns miss equivalents (an alias, a pipe to a shell, a different flag).
  • What runs without approval? Commits, pushes, deploys, and destructive commands should require human confirmation, not auto-run.

Memory and data

  • What's in memory files? Agent memory can accumulate secrets, customer data, or internal details. Treat it as sensitive storage.
  • Can tools read secrets? If a tool can read arbitrary files, assume it can read your secrets. Keep credentials out of reach.
  • Is PII entering prompts? Redact sensitive values before they're sent to a model.

MCP servers and external tools

  • Which MCP servers are configured, and what can they reach? A connector with network access widens the blast radius of any injection.
  • Are credentials committed in config? API keys in mcp.json or agent config are a classic leak.

Models and configuration hygiene

  • Are models pinned? An unpinned model can change behavior under you.
  • Are hooks over-permissive? Hooks that run on every tool call, or auto-approve actions, deserve scrutiny.

Make it repeatable

The point of a checklist is that it runs every time, not once. OpenRouting detects an agent setup during a scan and reviews it against exactly these dimensions — tool safety, secrets exposure, and config hygiene — so the check happens on every scan instead of living in someone's head. For a deeper engagement, you can also request a human expert review.

Keep reading