Teams are shipping LLM agents faster than they're reviewing them. An agent setup — the agent definitions, skills, memory stores, tool and MCP configurations, and the hooks that wire them together — is code and configuration like anything else, and it carries security weight that a normal code review often misses.
Here's a defensive checklist you can run against a repository today.
Tools and permissions
- Is every tool necessary? Remove tools the agent doesn't use. Each one is attack surface.
- Are file and shell tools scoped? A read tool with access to the entire filesystem can read
.env, credentials, and infra secrets. Scope it, and explicitly deny credential-bearing paths. - Is the permission model allow-list or deny-list? Prefer deny-by-default with an explicit allow-list. Deny-lists of dangerous patterns miss equivalents (an alias, a pipe to a shell, a different flag).
- What runs without approval? Commits, pushes, deploys, and destructive commands should require human confirmation, not auto-run.
Memory and data
- What's in memory files? Agent memory can accumulate secrets, customer data, or internal details. Treat it as sensitive storage.
- Can tools read secrets? If a tool can read arbitrary files, assume it can read your secrets. Keep credentials out of reach.
- Is PII entering prompts? Redact sensitive values before they're sent to a model.
MCP servers and external tools
- Which MCP servers are configured, and what can they reach? A connector with network access widens the blast radius of any injection.
- Are credentials committed in config? API keys in
mcp.jsonor agent config are a classic leak.
Models and configuration hygiene
- Are models pinned? An unpinned model can change behavior under you.
- Are hooks over-permissive? Hooks that run on every tool call, or auto-approve actions, deserve scrutiny.
Make it repeatable
The point of a checklist is that it runs every time, not once. OpenRouting detects an agent setup during a scan and reviews it against exactly these dimensions — tool safety, secrets exposure, and config hygiene — so the check happens on every scan instead of living in someone's head. For a deeper engagement, you can also request a human expert review.