Tools
Can the workflow email, browse, edit files, post publicly, update records, call APIs, or run code?
A quick no-login checklist for one AI workflow before a demo, pilot, client handoff, or public launch.
Can the workflow email, browse, edit files, post publicly, update records, call APIs, or run code?
Does it see customer records, support tickets, CRM notes, billing context, uploaded files, or private documents?
Can retrieved documents, saved context, previous conversations, or vector search affect later actions?
Are OAuth scopes, service accounts, MCP servers, or delegated user permissions broader than the workflow needs?
Can external pages, comments, files, tickets, or emails tell the model to ignore instructions or misuse tools?
Could tool-call history, endpoint names, schemas, debug traces, or error messages reveal internal systems?
Is there a clear list of actions the AI must never take, plus a human escalation path for uncertainty?
Can the team show what was tested, what remains risky, and the highest-priority fixes before users depend on it?
If two or more answers are vague, pause the launch path and tighten the workflow before real customer impact.
Do not send secrets, API keys, credentials, OAuth tokens, cookies, card or bank details, private payment pages, customer records, private handles, full names, full transaction IDs, or private dashboard screenshots.
The fixed-scope review covers one workflow and returns top risks, severity, rationale, and 3 prioritized fixes within 24 hours after scope and safe intake are complete.