Agent permission blast radius
Tick the scopes you are about to grant and see what a single successful prompt injection reaches. Scores the combinations as well as the parts, because permissions are reviewed one at a time and damage never is.
The thing most people get wrong
Read-your-files is survivable. Unrestricted egress is boring. Granted together they are the most common shape of a real incident, and the second checkbox is the one nobody argues about because it sounds like plumbing.
How to use it properly
- 1Tick exactly what the setup instructions ask for, including the ones that sound administrative. The scope people forget to count is almost always the one that turns a scare into a breach.
- 2Read the compounding pairs before the score. The score is a summary; the pairs are the argument, and each one names a real sequence rather than a category of risk.
- 3Untick one scope at a time and watch what the score does. The scope whose removal drops it the most is the one to go back to the maker about.
- 4Then check the listing. Where a verification found the software asks for more than it declares, that is a named finding on the page rather than something you have to discover yourself.
Embed this on your site, free
Use it in a blog post, a forum answer or a course. No permission needed, no attribution required beyond the link that comes with it.
<iframe src="https://ooruby.com/tools/agent-permission-blast-radius?embed=1" width="100%" height="620" style="border:1px solid #e0dcd3;border-radius:16px" title="Agent permission blast radius by ooruby" loading="lazy"></iframe>
<p style="font-size:13px;margin-top:6px">Powered by the <a href="https://ooruby.com/tools/agent-permission-blast-radius">agent permission blast radius</a> from <a href="https://ooruby.com">ooruby</a>.</p>