AI agent risk score
Answer 15 questions about one AI agent: what it can do, what it can reach, what it reads and who controls it. You get a risk tier (Critical, High, Medium, Low), the answers that raised it and the fix for each. Score every agent you run and download the list.
Your answers never leave your computer. The score is worked out in your browser.
Runs locally · 0 bytes uploaded
Your agents (0)
| Agent | Owner | Tier | Score |
|---|
How the score works
Each question has a risky answer: a capability (it can pay, it reads outside content) or a missing control (no owner, no kill switch). Each risky answer adds its weight; "Unsure" counts as risky, because an agent nobody can describe is a risk. The score is the sum, out of 38.
| Question | Risky answer | Adds |
|---|---|---|
| Q1 Can it take actions (send messages, change records, run code or workflows), not just answer questions? | Yes | +3 |
| Q2 Can it move money: pay, refund, buy, or approve payments? | Yes | +4 |
| Q3 Can it send to people outside the organisation (customers, suppliers, the public)? | Yes | +2 |
| Q4 Does a person approve before it sends, pays, deletes or publishes? | No | +3 |
| Q5 Does it run on a schedule or trigger with nobody watching? | Yes | +2 |
| Q6 Can it read personal, customer, financial or health data? | Yes | +3 |
| Q7 Does it have admin rights or write access to production systems? | Yes | +3 |
| Q8 Does it use its own account (not a person's login or a shared key)? | No | +2 |
| Q9 Are its keys or tokens kept in code, config files or chat, rather than a secrets manager? | Yes | +2 |
| Q10 Does it read content from outside (emails, web pages, documents, tickets) that could carry hidden instructions? | Yes | +3 |
| Q11 Can it call third-party tools, plugins or MCP servers? | Yes | +2 |
| Q12 Is there a named person accountable for it? | No | +3 |
| Q13 Can it be stopped within five minutes (a kill switch, a pause or a disabled account)? | No | +3 |
| Q14 Are its actions logged and kept for at least 90 days? | No | +2 |
| Q15 Has it been reviewed or tested for risk in the last 12 months? | No | +1 |
Tiers: Critical from 24, High from 15, Medium from 8, Low from 0. Two rules can raise the tier: an agent that can move money without a person approving is always Critical, and one that reads outside content and can act on it without approval (prompt injection) is at least High.
This is a first screening to prioritise your agents, not an audit or legal advice.