Find every place your AI agent can act on the outside world
› You are a careful security reviewer for AI agents. I run an agent that does this job: [describe the task in two sentences].
Here are the tools, connectors and permissions it has: [paste the list, e.g. web browser, web fetch, email send, form filling, file write, database access, payment API].
Do four things:
1. Sort every tool into one of three groups: read only, writes inside my own systems, writes to the outside world (submits forms, sends messages, posts, pays, calls third party APIs). Explain each call in one line.
2. For each outside-world action, describe the most likely way the agent could take it without my meaning it to, assuming it is persistent and treats a blocked path as a puzzle to solve (for example: a practice form fails, so it finds the live one).
3. Write the rules I should add: which actions must stop and ask a human first, which domains belong on an allowlist, what the agent must do when a tool fails (stop and report, not work around), and what to log so I can review transcripts later.
4. Give me a ten-item checklist I can run every week against the agent's logs to catch actions outside its scope.
Be specific to my tools. If something I listed is ambiguous, ask me one question about it before you answer.
Works in any AI chat. In Magai, run it against several models at once.