TKOResearch
Menu

AI Agent Blast-Radius Mapper

See what an AI agent can reach—and what happens if its controls fail.

Model tools, data, credentials, action authority, approval gates, validation, logging, and recovery. The mapper produces a live authority view and a prioritized control report.

Open the OWASP explorer

Live authority model

Current blast radius

Reachable systems and the agent's highest modeled authority.

4 connected systems

AI agent

MCP-connected assistant

write

Source code

Repositories, pull requests, issues, and workflows.

3 modeled gaps

send

Email

Mailboxes, drafts, messages, and recipients.

4 modeled gaps

read

Customer data

Profiles, orders, cases, and account records.

No modeled gaps

execute

Deployment

Build systems, environments, releases, and production.

4 modeled gaps

This mapper is a planning aid based on the authority and controls you select. It is not a certification, exhaustive threat model, or substitute for validating the deployed system.

Method

Authority determines impact.

Map reachable systems

List each system the agent can reach and distinguish read, write, send, and execute authority.

Model deterministic boundaries

Count controls only when code, policy, credentials, or human approval enforce them outside the model.

Prioritize control gaps

Focus first on paths that combine sensitive systems, external actions, production authority, and weak recovery.