Skip to content

Check an agent before you use it

Before accepting an agent from another person or team:

  1. Verify its owner, source, package identity, and exact fixed version.
  2. Identify where it runs and who can see plaintext.
  3. Confirm the model provider, account, retention terms, and permission to send it the data.
  4. Review required files, tools, network routes, and output targets.
  5. Test that an unapproved file and tool are denied.
  6. Confirm how updates are approved, future use is stopped, and past records are retained.
  7. Record the version, provider, limits, tests, approvals, and date.

Reject vague versions such as “latest,” unnecessary access, or behavior that does not match the stated controls.

For deeper checks, see Verify security claims.