Leash Index

Agent Permission Audit

What can your agent do to a customer’s account?

When a customer’s security review asks that question, this is the document you send back: every capability your agent holds, what each one can change, and the limits we recommend — dated and written to be read by someone who did not build it.

Who it is for

Teams shipping an AI agent or MCP server that acts inside customer systems, and facing a security review, a procurement questionnaire or an enterprise deal that turns on it.

What you receive

How it works

  1. You send your tool definitions: a tools/list response, an MCP configuration or function schemas. No access to production and no integration.
  2. We agree scope, price and timing with you before any work starts.
  3. We run the reading, review every finding by hand, and deliver the report.

Price

From $2,500 for a single agent or MCP server, up to $10,000 for several agents or servers reviewed together. You get a fixed quote before you pay.

What it is not

It is not a certification, not a penetration test, and not a statement that software is safe or unsafe. It describes what your agent is permitted to do, as declared, and how to bound it.

Independence

Buying an audit does not change any listing, score or ranking in the public index. If a server you maintain is listed, its page will carry a disclosure that you are a customer. See Independence.

Request an audit

We use these details only to reply about an audit, and never for marketing. See the Privacy Notice.

Prefer email? Write to support@leashkit.com. Media Yard LLC operates the Leash Index.