ciso.diy
Agentic AI Security Program Kit preview
Governance AI agentsagentic AIMCP securityprompt injection

Agentic AI Security Program Kit

Your AI agents can act — book, email, deploy, pay. Inventory them, fence them, test them, log them: 27 fields per agent, a blast-radius tier, a guardrail standard with per-action gates, OWASP ASI threat modelling with 18 test cases, and the playbook for the hour after one goes wrong.

What this actually gives you

  • An agent is an identity with privileges. Most AI-related breaches in 2025–26 involved systems with no access control at all.
  • Prompt injection arrives through what the agent reads — a web page, an email, a ticket, another tool’s output. The attacker never needs access to your agent.
  • Any agent that can pay, with internet reach, is Tier 1. The failure mode is not a wrong answer, it is a wire.
  • OWASP published its Top 10 for Agentic Applications in December 2025; the NCSC issued interim guidance; EU AI Act Articles 14 and 26 and ISO 42001 expect governed agents with logs.
  • The incident playbook’s first hour is stop, preserve, scope, reverse, contain, classify, notify — reversal is where agent incidents differ, because the actions may still be completing while you respond.

An agent is an identity with privileges. Most AI-related breaches in 2025–26 involved systems with no access control at all, and that is the whole problem in one line: the industry deployed a new class of privileged actor without giving it the treatment every other privileged actor gets — an inventory, a credential lifecycle, a scope, a log and a kill switch.

The vector is content, not access. Prompt injection arrives through what the agent reads — a web page, an email, a ticket, another tool's output. The attacker never needs access to your agent. Anything an agent consumes is untrusted input, and file 02's tool and data scoping is built on that assumption rather than on perimeter.

Any agent that can pay, with internet reach, is Tier 1. The failure mode is not a wrong answer, it is a wire. The inventory scores blast radius from what the agent can actually do — read, write, send, delete, execute, pay, spawn — and tiers it accordingly, so the controls land where the money and the destruction are.

The standards arrived in 2026. OWASP published its Top 10 for Agentic Applications in December 2025 — goal hijack, tool misuse, identity and privilege abuse, the agentic supply chain including MCP servers and agent cards, unexpected code execution, memory poisoning, insecure inter-agent comms, cascading failures, human-agent trust exploitation and rogue agents. The NCSC issued interim guidance. EU AI Act Articles 14 and 26 and ISO 42001 expect governed agents with logs. This kit is those expectations turned into an engineering standard you can enforce on Monday.

What you get

01 Agent Inventory & Permission Map (XLSX, 3 tabs) — 27 fields per agent covering runtime, model, protocols, tools, actions, identity, credential storage and lifetime, approval, autonomy and spend, resolving to a blast-radius score and tier. A Models tab for access mode, jurisdiction, weights source and format, loader flags and runtime exposure. A Tools & MCP registry with source, version pinning, capabilities, scopes, review status, sandboxing and approval.

02 Guardrail & Approval Standard (DOCX) — ten sections applied by tier: inventory, identity and credentials, tool and data scope, action gates for each of read / write / send / publish / delete / execute / pay / spawn, supply chain, isolation, monitoring and kill switch, change and testing, people, and exceptions.

03 Agent Threat Model & Test Plan (XLSX) — OWASP ASI01 to ASI10 crossed with the MCP-38 classes (tool-description poisoning, indirect prompt injection, parasitic tool chaining, dynamic trust violations), scored per agent for likelihood, impact and residual, plus 18 test cases behind a go-live gate.

04 Logging & Audit Requirements (DOCX) — the fields to capture per action, storage, retention, review cadence and who may read them. Written so that "we could not tell what it did" stops being an acceptable answer.

05 Agent Incident Playbook (DOCX) — triggers and the first hour in order: stop, preserve, scope, reverse, contain, classify, notify. Reversal is where agent incidents differ from every other kind — the actions may still be completing while you respond.

06 AI Vendor Addendum Cross-Reference (DOCX) — ten agent-platform delta questions with hard stops, written to append to the Vendor Risk Operations Kit's vendor addendum rather than duplicate it, plus contract terms for the TPRM Program Kit clause library.

07 Agent Metric Set (XLSX) — 14 metrics (AGM-01 to AGM-14) that name the Security Metrics & KPI Library's AI measures as their data sources rather than reinventing them.

08 Practitioner Guide (PDF) — the ecosystem in seven layers, models and weights, runtimes, protocols, identity, money, the ten threats, the programme, regulatory pull, a 90-day plan, failure patterns and an FAQ.

agent01.json — the tiering model, threat list, test-case ids and metric ids, machine-readable.

The model supply chain is treated as a supply chain. Hugging Face trust_remote_code and pickle formats execute code on load where safetensors and GGUF do not; revision pins get applied inconsistently; Talos found over a thousand publicly exposed Ollama servers. The Models tab captures weights source, format and loader flags precisely so those questions have somewhere to be answered.

An agent that can publish is a producer of synthetic media. Publish is its own action class, gated on disclosure applied before anything goes out — a visible label, the platform's native label, C2PA content credentials and a register row — plus a likeness or voice release where a real person is depicted. The obligations behind that gate, and the templates that discharge them, are the Synthetic Media & Deepfake Defense Kit. Treat Publish as the gate here and run the practice there.

Written to survive its own examples. Product, protocol and model names move quarterly. The standard in file 02 and the test plan in file 03 are written against capabilities and action classes, not vendors, and the licence says so plainly.

Pairs with the 2026 AI Risk Register for where agent risk is classified, scored and accepted, the EU AI Act Compliance Clock for the Article 14 and 26 duties that govern it, the Executive Tabletop Kit for the exercise, and I've Been Breached for when it becomes one.

The test cases include adversarial payload classes. Run them only in environments you own or are authorised to test, and never against a vendor platform without written permission.

What's included

  • Complete Library (.zip) — all formats included — fully editable
  • Instant download after purchase
  • Free updates — re-download when we release new versions
  • Practitioner License: unlimited client use (vCISO / MSP)

Choose your license:

  • Secure checkout via Stripe
  • All major cards accepted
  • 30-day satisfaction guarantee
Version 1.1
Last updated 2026-09-08
Pages 8
Version history
  • v1.1 2026-09-08

    Publish is now its own action class — an agent that can post is a producer of synthetic media, and the gate is disclosure before publication rather than access control.

    • File 02 §4: Publish split out of Send, gated on visible label, platform label, C2PA credentials and a register row, plus a likeness or voice release where a real person is depicted
    • New README section on content-producing agents, naming the Deepfake Defense Kit as the companion
    • agent01.json: publish added to action_classes, with a content_producing_agents block
  • v1.0 2026-09-04

    First release.

Already bought this? Every update is free — sign in to My Library for the current version.