Find where agent authority can escape its intended boundary.

I review agent workflows, MCP servers and automation paths before they become difficult to unwind. The result is a technical assessment with evidence, priorities and controls your team can implement.

The systems I review.

01

Agent systems

Identity, delegated authority, credentials, tool access and high-impact actions across an agent workflow.

02

MCP environments

Server authentication, tool descriptions, parameter boundaries, cross-server influence and request-level evidence.

03

Software supply chain

Packages, install scripts, CLIs, skills and external components that agents discover or execute.

Evidence your team can act on.

This is not a compliance checklist or a generic AI review. The work follows the real execution path through identities, tools, packages and infrastructure.

  1. 01A reviewed attack-path map
  2. 02Prioritized findings with severity and evidence
  3. 03Control recommendations tied to the actual architecture
  4. 04A working session with engineering and security

Your agents already touch systems that matter.

The assessment is most useful when a team has a working architecture, is approaching production, or needs to understand a concrete exposure before scaling.

CONTACT

Tell me what you’re building.

Reach out about Oktsec, AI agent security, technical assessments, advisory or talks. I work with a small number of teams where the problem is concrete and the work can be useful.

OR EMAIL DIRECTLYgus@oktsec.com

I only use this information to reply. No lists, no sharing.