Look twice.Find the gem.

AI agents and MCP servers, each published with its source and what the checks found.

Marketplace

  • Everything
  • AI agents
  • Apps
  • MCP servers
  • Templates
  • What people want
  • What changed this week
  • The verification standard
  • The ooruby Index
  • Servers that publish no source
  • Reliability guides
  • What the catalogue holds
  • Sell here

Our library

  • Everything, in one place
  • Guides
  • Glossary
  • Calculators
  • Checklists and cheat sheets
  • Community

ooruby

  • Home
  • For teams
  • Site status
  • Company projects
  • RSS feed

Verification records what our published tests found on a specific version at a specific date. It is not a warranty, and it does not certify that software is free of defects.

Rubricv1.0
AI agentsAppsMCP serversTemplatesWantedCommunityOur library
Sign inSell
Running it safely
All guides
Running it safelyIntermediate· 6 min read

Work out the blast radius before you grant a scope

The one thing to remember

Score the set, not the line. Read-your-files and unrestricted egress are each unremarkable, and together they are the most common shape of a real incident.

What you will be able to do

Decide a permission set you could defend afterwards, on the assumption that one prompt injection will succeed.

Figure

How Work out the blast radius before you grant a scope works, in one picture

1Assume the injection lands2List the scopes, including the administrative-sounding ones3Score the pairs, not the lines4Cut the scope with the largest single effect, then ask the m...5Grant it a credential that only does this job

The same argument as the text, as a chain. Each step is what makes the next one possible.

  1. 1

    Assume the injection lands

    Every useful version of this exercise starts by granting the attacker the win. An agent reads text it did not write: a web page, an email, a tool description. Some of that text will eventually be an instruction it follows.

    So the question is never whether it can be tricked. It is what it can reach in the minute after it is, and that is entirely decided by what you ticked during setup.

  2. 2

    List the scopes, including the administrative-sounding ones

    The calculator on this page, and at /tools/agent-permission-blast-radius

    Write down every permission the setup asks for, in its own words. The one people forget is never the frightening one; it is the one that reads like plumbing. Network access. Environment variables. A webhook.

    Those are exactly the scopes that turn a contained problem into a disclosure, because they are how the other permissions get their results out.

  3. 3

    Score the pairs, not the lines

    Read credentials, on its own, is a bad afternoon. Read credentials plus reach any host is a breach, and nobody objected to the second one. Write files plus run commands is arbitrary code execution assembled from two ordinary requests.

    This is why permission review as a checklist fails: each line passes on its own merits and the set is indefensible. Review the set.

    The pair that catches the most people is read-files with unrestricted egress, because neither half looks like anything.

  4. 4

    Cut the scope with the largest single effect, then ask the maker

    Remove one permission at a time and see which removal changes the picture most. That scope is the conversation to have with the maker, and the good ones have an answer: a narrower integration, a read-only mode, a declared host list.

    Where the answer is that it needs everything because it is easier that way, you have learned something about the software that no test result would have told you.

  5. 5

    Grant it a credential that only does this job

    Never hand over a personal token carrying your own access. Issue a scoped one, and know how to revoke it before you grant it rather than while you need to.

    Then rotate whatever you gave it on the day you stop using it. An agent you uninstalled and a credential you left live are not the same decision, and only one of them was made.

    If the setup instructions ask for a personal token, that is a question for the maker before it is a problem for you.

Try it
You have got it when

You can name the worst legal thing your permission set allows, in one sentence, without checking.

Open the catalogue on ooruby

Read next

Before you buy
Permissions worth refusing
Glossary
Blast radius
Glossary
Least privilege
Running it safely
The first week with a new agent
Running it safely
Why agents fail in production, and what to watch
Running it safely
Try a listing before you pay
The bottom line

Score the set, not the line. Read-your-files and unrestricted egress are each unremarkable, and together they are the most common shape of a real incident.

See the AI and semiconductor names

The near-monopolies and the commodities, side by side, because they look identical from outside and they are not.

Blast radius of the scopes you grantedInteractive
Scopes granted
2
Compounding pairs
1
Blast radius
Serious
Why the pairs matter more than the parts

Read plus unrestricted egress is exfiltration with extra steps.

Tick read-files and unrestricted egress together. Neither is alarming on its own, and the pair is the most common shape of a real incident.