Execution boundary
Tool authorization, tenant isolation, human approval, sandboxing and network egress — not prompt guardrails alone.
Paste or import Agent/MCP configuration and code for a browser-only static scan of shell execution, secrets, remote MCP, egress, permissions, retention, logging and execution limits; then verify runtime and governance controls that static analysis cannot prove.
Tool authorization, tenant isolation, human approval, sandboxing and network egress — not prompt guardrails alone.
Model APIs, remote MCP, memory, vector stores, files, traces, audit records and third-party SaaS belong in one retention map.
Production systems need anomaly monitoring, credential revocation, tool/MCP disable controls and minimum-necessary audit evidence.
The static scanner is rule-based and only analyzes text supplied in the current browser; common secret patterns are redacted in displayed evidence. Governance verification covers execution-time authorization, tenant boundaries, third-party retention, monitoring and incident response that a snippet cannot prove. The method follows XBSTACK's Agent Security Infrastructure framework and is informed by NIST, OWASP Agentic Top 10 and the MCP specification; it is not a certification standard.
No. Configuration/code scanning, evidence extraction, scoring, Markdown generation, and JSON export run in the current browser. XBSTACK does not receive the Agent/MCP configuration or governance answers you paste or import.
No. It is an engineering risk screen and production-readiness checklist, not a security certification, legal opinion, GDPR/HIPAA attestation, threat model, code audit or penetration test.
Because tool visibility is not authorization. A production system should re-check identity, tenant, resource, scope and parameters after the model proposes a tool call and before the real executor performs the action.
ZDR controls eligible OpenAI API retention behavior. Remote MCP servers, third-party SaaS, application memory, vector stores, files, traces and audit logs remain separate retention boundaries.
No. Roots are protocol-level capability and boundary signals. They do not replace process, filesystem, network, credential and host isolation for code or shell execution.
No. Redlines override the score. Missing execution-time authorization, missing tenant isolation, direct host-sensitive code execution, irreversible actions without authorization/approval, or sensitive egress to third parties with unknown retention can force NOT PRODUCTION READY.