A weekly security audit workflow for AI agents: supply chain, prompt injection, MCP and more
alexcovo_eth · x · 2026-10-07
A practical, reusable security audit routine for AI agents like Hermes:
- Start with the native hermes security audit for a real supply-chain check.
- Then have the agent inspect its full exposed surface weekly: secrets & API keys, files & permissions, prompt injection, email & phishing, data exposure, plugins/MCP/skills, remote & browser access, cron/webhooks/unattended jobs, and logs/backups/stale access.
Two rules: no evidence means no confirmed vulnerability (mark it UNKNOWN), and audit first — fix only after approval. The author shares the full weekly prompt, making the workflow directly reproducible.
More from coding & agent
- Codex Can Now Control Electron Apps and Test, Debug Them Directly — JeremyNguyenPhD · 2026-10-07
- AI Security Institute open-sources Transect, turning agent transcripts into interactive timelines — joshua_saxe · 2026-10-07
- Brian Balfour: building an agentic growth mechanic when AI makes growth a search problem — morganb · 2026-10-07
- "Agent says it's done" isn't ready: passing tests only cover a fraction of ship-readiness — Glittering-Glass6135 · 2026-10-07
- A changelog prompt keeps your Grok Bot updated on its own improvements in long-running jobs — RachelVT42 · 2026-10-07
- opencode v2 bug: Bedrock inference profile ARNs get Nova-format reasoning config for Claude models — gillespied · 2026-10-07