No obligation
A free agentic risk assessment.
We test the agents, MCP servers, and AI applications you already run. You get every path that opened, reproduced step by step, with the order to fix them in.
Run by the team that graded 2,706 organizations for the same exposures and published the method.
- Reply
- one business dayWith a written scope for you to approve
- Testing
- 5 business daysOnly against endpoints you named
- Readout
- 45 minutesLive, with the engineer who ran it
Nothing is touched until you approve the scope in writing.
A finding from a real report
This is what arrives.
One finding, in the form your engineers receive it.
An unauthenticated MCP server exposes 47 tools, among them create_listing and checkout.
Reproduction
POST /sse {"method":"initialize"}200 OKPOST /sse {"method":"tools/list"}47 toolsSame two calls, from a browser on any originpermitted
No credential was supplied at any point. The third line is what turns this from an exposed server into a path: a page in a teammate’s browser can run it.
Blast radius
Listing creation, checkout, and refund issuance, attributed to nobody. The tools are real, they are callable, and the server volunteers their names on request.
Fix. Put the server behind OAuth with short-lived tokens and scope the CORS policy to your own origins.
~2 hrsWhat makes it usable
Four things every finding carries, so it can be actioned without a follow-up call.
- Filed where your auditors look
- Every finding carries its OWASP Top 10 for Agentic Applications category, so it lands in a framework your GRC team already reports against.
- The endpoint, named
- The host, its authentication posture, and its CORS policy. Redacted in this specimen. In your report it names your systems.
- Reproduced, not asserted
- The requests we sent and what came back. Your engineer can rerun the finding line by line and watch it happen.
- A fix, with its cost
- What closes it and roughly what that takes, so the finding can be scheduled instead of debated.
And five more sections around it.
Report contents- 01
Exposure map
Every agent, MCP server, model endpoint, and orchestrator we can attribute to your domain from the outside, each with its authentication posture and the tools it volunteers.
- 02
Findings, reproduced
Each one built like the specimen above: the endpoint, the requests, the responses, the blast radius, and the fix.
- 03
Attack paths
Where one finding unlocks the next. A read-only disclosure and a permissive origin policy are minor apart and an incident together.
- 04
OWASP ASI mapping
The whole set filed by category against the OWASP Top 10 for Agentic Applications, ready to drop into the reporting you already do.
- 05
Fix order
What to close this week and what can wait a quarter, ranked by blast radius rather than by severity label, each with an estimate.
- 06
Board summary
One page, no jargon, defensible. The artifact you forward when someone upstairs asks what you are doing about AI risk.
Then 45 minutes on a call with the engineer who ran it. You get the reasoning behind the ranking, not a PDF thrown over the wall.
How it runs
- Today
You tell us what you run
The form on this page. A domain, the surfaces you have, and anything you specifically want pressure-tested.
- Within one business day
We scope it in writing
Targets, rules of engagement, and a window. Nothing is touched until you approve that document.
- About 5 business days
We run it
Passive attribution first, the view an attacker gets for free. Then active probes, only against endpoints you named.
- 45 minutes
You get the readout
The findings, the paths, and the fix order, walked through live by the engineer who ran them.
What we will and will not touch
The first question every security team asks. Here is the answer before you fill in anything, and it is the same text that goes into the scope document you sign.
We will
- Enumerate what is already public, read-only, from outside your perimeter
- Probe only the endpoints named in the scope you signed
- Prove a path is reachable, then stop
- Show you every finding before anyone else sees it
We will not
- Send payloads or log in during discovery
- Touch anything the scope document does not name
- Invoke a write, payment, or exec tool
- Publish anything, or name you, without written consent
The grading logic behind the discovery half is published in full.
Questions people ask first
Is it actually free?
Yes. No cost, no obligation, no requirement to buy anything afterwards. We do it because most teams do not know what their agents expose, and the fastest way to show what Guard0 does is to show you your own estate.
Is this a penetration test?
No. A pentest covers your whole application surface against a broad threat model. This is narrower and deeper: the agent layer specifically, meaning MCP servers, tool permissions, agent identity, memory, and the paths between them. It complements a pentest, it does not replace one.
Do you need access to our systems?
Not for the discovery half. We start from your domain and work the way an attacker does, from the outside. Active testing needs only the endpoints you approve, and we ask for credentials only if you want authenticated paths covered.
How long does it take?
About 5 business days from signed scope to readout. We reply to your request within one business day with times.
What if you find nothing?
Then you get that in writing, which is worth having. An A grade with the methodology attached is a defensible answer to an auditor asking how you know.
Can I see what you find before talking to anyone?
Yes. The AI Register runs the passive half of this assessment on its own, free, with no login and no sales contact. Start there if you would rather look first.
What happens next
You will know what your agents expose in about 5 business days.
It costs nothing, nothing runs until you approve the scope, and the findings are yours either way. Or run the passive half yourself right now and see your grade in a minute.
Would rather talk it through? Book 30 minutes.