How safely are your AI agents wired into your systems?
Five surfaces decide whether agent integrations are safe — access, data exposure, actions, server trust and oversight. Answered from how your integrations actually work, and scored the moment you finish.
Your level, five-dimension profile and recommendations appear on screen the moment you finish — no email, and the branded PDF report is yours to keep.
01Access & Permissions
02Data Exposure
03Action Safety
04Server Trust
05Oversight & Governance
Scored in this browser — nothing is sent unless you choose to.
Written by DigiWagon’s delivery practiceScored with the published DigiWagon MCP Security FrameworkISO/IEC 27001 and ISO 9001 certifiedWork we’ve delivered
This check is an educational self-assessment, not a security audit or penetration test — a real review examines code, configuration and traffic. It shows you where that deeper look should start.
Who this is for
CTOs and engineering leads wiring AI agents into real systems
Security leads asked to review an agent deployment
Founders adding MCP-powered features to their product
The flow
How it works
01Answer quick multiple-choice questions about how your agent integrations actually work — options, not essays.
02Get your level and a five-surface profile, scored against the published rubric.
03Keep the branded PDF report — and send your results through if agents are heading for production.
Every result is one level and five surface scores — an example profile.
The framework
Five surfaces, scored in the open
Every answer carries zero to three points by the maturity it describes. Three questions per surface give a surface score out of nine; the five surfaces together map to one of four levels. The rubric is published because a score you can't inspect isn't worth acting on.
0–3 per answer→3 questions per dimension→dimension score out of 9→5 dimensions→your result out of 45
No gate. Full results on screen — email is never required to see them.
Nothing stored. Answers are scored in your browser and never leave this page unless you choose to send them.
No invented benchmarks. Every number derives from the published rubric and your own answers.
All five dimensions weigh equally in v1 — deliberately, until real-world results earn differentiated weights. Framework v1 · September 2026.
What your agents' connections can actually reach: the scopes behind each integration, how credentials are handled, and who can wire up something new.
Why this matters
An agent inherits every permission its connections carry. Broad scopes turn a single bad tool call — or a single hijacked session — into access to everything the account could ever touch.
What can your agents' MCP connections actually reach?
How are the credentials behind your MCP servers handled?
Who can add a new MCP server or tool to an agent?
02
Data Exposure
What tools can return into the model's context, where conversation and tool-call data ends up, and whether regulated data can flow through an agent unnoticed.
Why this matters
Everything a tool returns becomes model context — and potentially provider-side data. The question isn't whether agents see data; it's whether anyone decided which data, and where it's allowed to go.
What data can tools return into the model's context?
Where does conversation and tool-call data end up?
Could regulated or confidential data flow through an agent today?
03
Action Safety
What agents can do beyond reading — writes, sends, deletes — what stands between an agent and an irreversible action, and how a misbehaving run gets stopped.
Why this matters
Reading exposes data; acting changes the world. The costliest agent incidents are actions — the sent email, the deleted records, the modified order — and they arrive at machine speed unless something is designed to stand in the way.
What can your agents do, beyond reading?
What stands between an agent and an irreversible action?
If an agent misbehaved mid-task, how would it stop?
04
Server Trust
Where your MCP servers come from, whether tool outputs are treated as untrusted input, and how updates reach you — the supply chain of your agent stack.
Why this matters
An MCP server runs with the credentials you gave it, and whatever a tool returns goes straight into the model's context — which makes unvetted servers and unfiltered outputs the two front doors for prompt injection and worse.
Where do your MCP servers come from?
How do you treat what tools return to the model?
How do server updates and changes reach you?
05
Oversight & Governance
Whether you could reconstruct what an agent did, whether policy governs what agents may connect to and do, and what happens the night something leaks.
Why this matters
Agents act on your behalf at machine speed — oversight is what makes that delegation accountable. Without an audit trail and a policy, every incident starts with 'we're not sure what it did.'
Could you reconstruct what an agent did last Tuesday?
Is there a policy for what agents may connect to and do?
If an agent leaked data tonight, what would happen?
What your score means
Exposed0–13 of 45
Your agents currently hold more power than your controls account for — broad access, unguarded actions, or servers nobody vetted. The good news: the first fixes are design decisions, not projects. Scopes, approval gates on writes, and central logging change your position in weeks; start with the lowest surface below.
Experimenting14–24 of 45
Typical of teams moving fast with agents — real capability, controls trailing behind. The pattern to break is 'we'll harden it later': every integration added now sets a precedent. Pick the two surfaces that scored lowest and bring them level before the next connection ships.
Controlled25–35 of 45
The fundamentals are deliberate — scoped access, guarded actions, a trail you could follow. What separates you from production-grade is consistency under growth: every new server, tool and agent inheriting the controls automatically rather than by someone remembering.
Production-Grade36–45 of 45
Your agent integrations are governed the way production systems deserve — least privilege, engineered action safety, vetted supply chain, queryable oversight. That posture is a competitive asset: it's what lets you say yes to more autonomy, faster, while others are still writing the policy.
FAQ
About this check
Short answers to what people ask before they take it — and what a self-assessment can and cannot tell you.
01What is MCP — the Model Context Protocol?
MCP — Model Context Protocol — is an open standard that lets AI models and agents connect to outside systems through a common interface: databases, SaaS tools, file stores and internal APIs. Each connection is an MCP server exposing tools the agent can call, which is precisely why access, actions and oversight need deliberate design.
02What does this check measure?
Five surfaces where MCP integrations go wrong: access and permissions, what data tools can expose into model context, the safety of actions agents can take, trust in the servers you install, and the oversight around it all. Three questions each show which surface needs attention first.
03Is this a security audit or penetration test?
No. This is an educational self-assessment: you answer from how your integrations actually work, and it shows where risk likely concentrates. A real security review examines your code, configurations and traffic. The check tells you whether that deeper review is urgent — and where it should start.
04Do I need to share my email address to see the results?
No. Your score, the five-surface breakdown and every recommendation appear on screen the moment you finish, and the branded PDF report generates locally in your browser. Contact details only come into it if you choose to send your results to our team for an agent-security conversation.
05We haven't deployed MCP yet — is this still useful?
Yes — arguably most useful before deployment. Answer for the integration you're planning rather than one you run, and the gaps become your pre-launch checklist: scopes to define, approval gates to design, logging to switch on. Retaking it after go-live shows whether the plan survived contact.
06What should we do with a low score?
Start with Action Safety and Access — they decide the blast radius of everything else, and both usually close with design rather than tooling: least-privilege scopes, approval gates on writes, and treating tool outputs as untrusted input. Send your results through and we'll walk the gaps with you.
Taking agents to production?
Send your results through and we'll walk the gaps with you — scopes, approval gates, server vetting and the audit trail — against how we build governed agents for production. A working conversation, not a pitch.
One click opens the assistant you already use with a question that points it at this page, so the answer comes from what we publish, not a guess.
The question it opens withRead https://digiwagon.com/tools/mcp-security and tell me what "MCP Security" helps me decide, what inputs I should gather before using it, and how DigiWagon suggests acting on the result. Stick to what the page says and mark anything you are not sure about.