Work out the blast radius before you grant a scope
Score the set, not the line. Read-your-files and unrestricted egress are each unremarkable, and together they are the most common shape of a real incident.
Decide a permission set you could defend afterwards, on the assumption that one prompt injection will succeed.
How Work out the blast radius before you grant a scope works, in one picture
The same argument as the text, as a chain. Each step is what makes the next one possible.
- 1
Assume the injection lands
Every useful version of this exercise starts by granting the attacker the win. An agent reads text it did not write: a web page, an email, a tool description. Some of that text will eventually be an instruction it follows.
So the question is never whether it can be tricked. It is what it can reach in the minute after it is, and that is entirely decided by what you ticked during setup.
- 2
List the scopes, including the administrative-sounding ones
The calculator on this page, and at /tools/agent-permission-blast-radiusWrite down every permission the setup asks for, in its own words. The one people forget is never the frightening one; it is the one that reads like plumbing. Network access. Environment variables. A webhook.
Those are exactly the scopes that turn a contained problem into a disclosure, because they are how the other permissions get their results out.
- 3
Score the pairs, not the lines
Read credentials, on its own, is a bad afternoon. Read credentials plus reach any host is a breach, and nobody objected to the second one. Write files plus run commands is arbitrary code execution assembled from two ordinary requests.
This is why permission review as a checklist fails: each line passes on its own merits and the set is indefensible. Review the set.
The pair that catches the most people is read-files with unrestricted egress, because neither half looks like anything.
- 4
Cut the scope with the largest single effect, then ask the maker
Remove one permission at a time and see which removal changes the picture most. That scope is the conversation to have with the maker, and the good ones have an answer: a narrower integration, a read-only mode, a declared host list.
Where the answer is that it needs everything because it is easier that way, you have learned something about the software that no test result would have told you.
- 5
Grant it a credential that only does this job
Never hand over a personal token carrying your own access. Issue a scoped one, and know how to revoke it before you grant it rather than while you need to.
Then rotate whatever you gave it on the day you stop using it. An agent you uninstalled and a credential you left live are not the same decision, and only one of them was made.
If the setup instructions ask for a personal token, that is a question for the maker before it is a problem for you.
You can name the worst legal thing your permission set allows, in one sentence, without checking.
Read next
Score the set, not the line. Read-your-files and unrestricted egress are each unremarkable, and together they are the most common shape of a real incident.
The near-monopolies and the commodities, side by side, because they look identical from outside and they are not.