Map identity, tool, data, action, policy, and evidence together.
A single prompt can influence tool selection; over-broad identity access can turn that choice into a sensitive action. The assessment model connects discovery, authorization, runtime evaluation, and evidence.
RazorShark Security is a fictional company created by Luasai for product demonstrations. Products, scenarios, and company information are illustrative.
Assessment scope
- Agent and non-human identity ownership
- API, application, data, and MCP tool access
- Allowed, review-required, and prohibited actions
- Indirect prompt injection and unsafe parameter paths
- Evidence required for security, investigation, and risk review
