The method

Prove, report,
then block.

One object: the action — what your agent executes through its tools. We prove it can be hijacked, we document every scene, and the ActionShield software will cut the action before the tool. Always on your sandbox, never on prod without a mandate.

The framework

20 min
the proof on your sandbox
5 days
the report delivered
0
production action without written mandate
1
object: the action, not the talk

The three steps

Step 1

The proof (20 minutes)

On your sandbox: we show one action your agent should not be able to take. If we find nothing, you pay nothing. Fear is not announced, it is demonstrated.

Step 2

The report (5 days)

Tool and action inventory, documented injection scenes, attempted exfiltration chains, business-impact prioritization. Reusable as-is in your client questionnaires.

Step 3

The layer (the software, soon)

The ActionShield software: the proxy in front of your tools — in spec, allow; out of spec, block + journal. In development, tested early by design partners.

What we attack, exactly

Injection through read content

A ticket, a document, a resume, a dependency README: any text your agent reads can carry an instruction — and it obeys.

Tool poisoning

An instruction hidden in a tool's description or return — typically an MCP server your agent calls without reading it fully.

In-spec exfiltration

The attack that goes through allowed actions: a legitimate mail whose body contains what a sensitive tool just read. The scene no naive allowlist cuts.

Perimeter abuse

The gap between mounted tools and granted tools: what your agent can access, who decided, and where it is written. Nowhere, usually.

The rules of engagement

  • Sandbox provided and controlled by the client — the provided access is the mandate.
  • Systematic written authorization before any mission.
  • Zero data retention, documented cleanup.
  • Responsible disclosure aligned with ISO 29147.
  • Findings mapped to OWASP Top 10 for Agentic Applications (ASI02, ASI03) and MITRE ATLAS (AML.T0053).
  • Zero attribution in test artifacts: nothing traceable to the operator.

What we never do

  • No testing on your production without written mandate.
  • No scanning of third-party systems, no unauthorized access.
  • No massive data extraction — we confirm readability, we stop.
  • No modification of your real data.

What you receive

The report

Short, readable, written for your client questionnaires and your team — every finding with its reproducible proof and what would have cut it.

The action spec

Black on white: what your agent is allowed to do, tool by tool, argument by argument. The deliverable nobody else produces.

The layer (soon)

The ActionShield software deployed on your side: every action checked against the spec, every decision journaled. Design partners test it first.

FAQ

Want to know what your AI agent can do?

Tell us about your agent, its tools, and client context. We will come back with the right review scope.

Discuss your audit