APIs & Agentic AI
Agent blast-radius calculator
Assume the agent misuses every tool it has. What is the worst outcome, what is irreversible, and do your controls actually constrain it?
Compare your assumptions
The captured baseline stays fixed while you edit the proposed inputs below. Edit baseline inputs loads it into the working form; capture again to save your changes. Differences are proposed minus baseline, without a better/worse judgement.
- Exposure score (score)
- Baseline: 30
- Proposed: 30
- Difference: 0
- Destructive tools (tools)
- Baseline: 2
- Proposed: 2
- Difference: 0
- Irreversible tools (tools)
- Baseline: 3
- Proposed: 3
- Difference: 0
Save inputs locally to resume this tool. Files may contain sensitive entered information; review before sharing. No automatic storage or transmission. Report JSON is an output record, not an input import format.
Security review does not ask whether the model is good. It asks: assuming it does the wrong thing with every tool it has, what is the worst outcome, and can we undo it? That is answerable from the tool definitions alone.
Controls shrink the radius; they do not shrink the tool set. The only tool that cannot be misused is one the agent does not have — which is why we argue the work sits in scoping the layer beneath the model, not in prompt engineering above it.
Categorisation is inferred from tool names, descriptions and MCP safety annotations. It is a prompt for the conversation a reviewer should have, not a substitute for reading the implementations — a tool called get_report that quietly writes an audit row will be scored as read-only here. Runs in your browser.
More in this category
These exist because the underlying problem is real. If the numbers you just put in look uncomfortable, that is usually worth a conversation.
Stay ahead of the integration layer.
Integronauts Signal — practical enterprise integration, API and agentic AI thinking. The tools stay free either way.
Integronauts Signal is launching soon.
Practical enterprise integration, APIs, agentic AI and emerging architecture. Sign-up opens when the list does — nothing to enter yet.

