Agent access review worksheet
Compare supplied agent permissions and tool declarations with its stated task and prepare a least-privilege review worksheet.
Requested access
Uses supplied, redacted source material only. Produces a draft or review; does not fetch external data, run commands, send messages or modify systems.
Example input or starter prompt
Task: answer questions from approved docs. Declared tools: docs.read and repository.write. Runtime evidence unavailable.
Example output
docs.read — supports the stated task; confirm collection scope. repository.write — needs justification; no edit workflow supplied. Proposed check: ask the owner whether edits are part of the workflow, then test a narrower permission in staging. Runtime enforcement remains unverified.
Usage and setup instructions
Download and review the skill, then supply the redacted inputs described in its instructions. Ask your agent to follow the skill for the requested task. The example is illustrative, not a recorded execution.
Compatibility and prerequisites
Plain-text instructions for agents that support Markdown skills. No external integration required; client-specific installation must be checked.
Limitations
Uses supplied evidence only. Does not verify external systems or execute changes. Outputs require review; examples illustrate the intended format.
Source · agent-access-review.md
---
name: agent-access-review
description: Compare supplied agent permissions and tool declarations with its stated task and prepare a least-privilege review worksheet.
---
# Agent access review worksheet
Use this to review a supplied agent task description, normalized config and optional deterministic scan findings. It does not connect tools, change permissions or certify an agent as safe.
## Workflow
1. List the concrete operations needed for the stated task, including reads, writes and external destinations. If the task is vague, mark the required access unknown rather than recommending broad permissions.
2. Map every declared permission and tool to a task operation, resource scope and approval requirement. Distinguish a declaration from verified enforcement. Tool names alone do not prove read-only behavior.
3. Identify access without a stated purpose and narrower alternatives as review questions. Preserve supplied scanner rule IDs, severity, scores and pass/fail outcomes exactly; do not generate new authoritative findings or scores.
4. For each proposed reduction, explain the workflow it may break, a local or staging verification step, the responsible owner if supplied and a rollback consideration. Never recommend testing destructive access on production.
## Output
Return Task and evidence, Permission-to-purpose mapping, Proposed changes for review, and Unverified assumptions. Use “needs justification” for access whose purpose is unknown, not “vulnerability confirmed.” Do not ask for credential values or reproduce secrets in excerpts.
Example: a documentation assistant with repository write access needs justification; recommend checking whether its actual workflow creates edits before removing that access. A clean static scan is not proof of runtime least privilege.
Deterministic scan evidence · Grade A
0 findings from a static scan of this exact source. No instructions were executed. Linked files, real tool permissions and runtime behavior are not verified.
Reuse and attribution
This file is provided under the MIT license. Keep the accompanying copyright and permission notice when redistributing. Files are supplied without warranty.
View license