---
name: agent-access-review
description: Compare supplied agent permissions and tool declarations with its stated task and prepare a least-privilege review worksheet.
---

# Agent access review worksheet

Use this to review a supplied agent task description, normalized config and optional deterministic scan findings. It does not connect tools, change permissions or certify an agent as safe.

## Workflow
1. List the concrete operations needed for the stated task, including reads, writes and external destinations. If the task is vague, mark the required access unknown rather than recommending broad permissions.
2. Map every declared permission and tool to a task operation, resource scope and approval requirement. Distinguish a declaration from verified enforcement. Tool names alone do not prove read-only behavior.
3. Identify access without a stated purpose and narrower alternatives as review questions. Preserve supplied scanner rule IDs, severity, scores and pass/fail outcomes exactly; do not generate new authoritative findings or scores.
4. For each proposed reduction, explain the workflow it may break, a local or staging verification step, the responsible owner if supplied and a rollback consideration. Never recommend testing destructive access on production.

## Output
Return Task and evidence, Permission-to-purpose mapping, Proposed changes for review, and Unverified assumptions. Use “needs justification” for access whose purpose is unknown, not “vulnerability confirmed.” Do not ask for credential values or reproduce secrets in excerpts.

Example: a documentation assistant with repository write access needs justification; recommend checking whether its actual workflow creates edits before removing that access. A clean static scan is not proof of runtime least privilege.
