Saratoga Labs

AI Security Tool

Map how your organization discovers, connects, and governs AI agents — then run an attack scenario against that architecture to see how far a compromise would spread.

Discovery

0 selected

How agents in your environment get found.

Connections

0 selected

What agents in your environment can reach.

Enforcement

0 selected

How agent actions get controlled or stopped.

Attack scenario

A malicious instruction hidden in retrieved content tries to redirect an agent into taking an unintended action.

0
Risk Index
Not yet simulated

Select your discovery, connection, and enforcement coverage, then run a scenario to see how far it would spread.

No simulation run

Nothing has been simulated yet — pick your coverage above and run a scenario.

What this tool does

The AI Security Tool models the three layers that decide how far an attack against an AI agent can travel: how agents are discovered, what systems those agents can reach, and what enforcement stands between an agent action and a real consequence. You select the controls you actually have in place, choose an attack scenario, and the simulation reports the likely blast radius and how the incident would most plausibly resolve. Nothing is uploaded, scanned or stored — it is a reasoning aid built from the same questions we ask during an advisory engagement.

Why agent security is different

Traditional application security assumes a program does only what its code says. An AI agent takes instructions from text it reads at runtime, which means a document, a webpage, a support ticket or a calendar invite can become an instruction channel. The agent then acts with whatever credentials it holds. So the risk is rarely the model itself — it is the combination of an untrusted input path, a broad credential, and no enforcement point between the agent and a production system. Prompt injection, credential theft and lateral movement are the three shapes this failure usually takes.

How to read your result

A contained result means an attacker who compromises one agent is stopped before reaching data or systems that matter. A spreading result means the compromise inherits the agent's reach — usually because connections are broad and enforcement is advisory rather than blocking. If discovery is missing, treat every result as optimistic: you cannot protect agents you have not inventoried, and shadow agents built by individual teams are the most common gap we find. The practical order of improvement is inventory first, then narrow credentials, then add an enforcement point that can actually refuse an action.

About the author

Written and maintained by Louis Torres, Director at Saratoga Labs, drawing on two decades of audit, regulatory compliance and technology advisory work with banks, credit unions and professional-services firms. Questions or a request for a formal assessment: louis@saratogasprings.io.