Skip to content

No obligation

A free agentic risk assessment.

We test the agents, MCP servers, and AI applications you already run. You get every path that opened, reproduced step by step, with the order to fix them in.

Run by the team that graded 2,706 organizations for the same exposures and published the method.

Reply
one business dayWith a written scope for you to approve
Testing
5 business daysOnly against endpoints you named
Readout
45 minutesLive, with the engineer who ran it

Nothing is touched until you approve the scope in writing.

Request your assessment

Tell us what you run. We scope the assessment around it and send times.

What should we look at?

Work email only. We reply within one business day. Nothing is tested without your written approval.

A finding from a real report

This is what arrives.

One finding, in the form your engineers receive it.

Specimen · finding 03 of 11ASI02 Tool MisuseCritical

An unauthenticated MCP server exposes 47 tools, among them create_listing and checkout.

mcp.redacted.com/sseauth noneCORS *

Reproduction

  1. POST /sse {"method":"initialize"}200 OK
  2. POST /sse {"method":"tools/list"}47 tools
  3. Same two calls, from a browser on any originpermitted

No credential was supplied at any point. The third line is what turns this from an exposed server into a path: a page in a teammate’s browser can run it.

Blast radius

Listing creation, checkout, and refund issuance, attributed to nobody. The tools are real, they are callable, and the server volunteers their names on request.

Fix. Put the server behind OAuth with short-lived tokens and scope the CORS policy to your own origins.

~2 hrs
Reconstructed from an anonymized field note in The State of Exposed Agents. One of 1,139 servers we found answering to anyone. Yours will name your systems.

What makes it usable

Four things every finding carries, so it can be actioned without a follow-up call.

Filed where your auditors look
Every finding carries its OWASP Top 10 for Agentic Applications category, so it lands in a framework your GRC team already reports against.
The endpoint, named
The host, its authentication posture, and its CORS policy. Redacted in this specimen. In your report it names your systems.
Reproduced, not asserted
The requests we sent and what came back. Your engineer can rerun the finding line by line and watch it happen.
A fix, with its cost
What closes it and roughly what that takes, so the finding can be scheduled instead of debated.

And five more sections around it.

Report contents
  1. 01

    Exposure map

    Every agent, MCP server, model endpoint, and orchestrator we can attribute to your domain from the outside, each with its authentication posture and the tools it volunteers.

  2. 02

    Findings, reproduced

    Each one built like the specimen above: the endpoint, the requests, the responses, the blast radius, and the fix.

  3. 03

    Attack paths

    Where one finding unlocks the next. A read-only disclosure and a permissive origin policy are minor apart and an incident together.

  4. 04

    OWASP ASI mapping

    The whole set filed by category against the OWASP Top 10 for Agentic Applications, ready to drop into the reporting you already do.

  5. 05

    Fix order

    What to close this week and what can wait a quarter, ranked by blast radius rather than by severity label, each with an estimate.

  6. 06

    Board summary

    One page, no jargon, defensible. The artifact you forward when someone upstairs asks what you are doing about AI risk.

Then 45 minutes on a call with the engineer who ran it. You get the reasoning behind the ranking, not a PDF thrown over the wall.

How it runs

  1. Today

    You tell us what you run

    The form on this page. A domain, the surfaces you have, and anything you specifically want pressure-tested.

  2. Within one business day

    We scope it in writing

    Targets, rules of engagement, and a window. Nothing is touched until you approve that document.

  3. About 5 business days

    We run it

    Passive attribution first, the view an attacker gets for free. Then active probes, only against endpoints you named.

  4. 45 minutes

    You get the readout

    The findings, the paths, and the fix order, walked through live by the engineer who ran them.

What we will and will not touch

The first question every security team asks. Here is the answer before you fill in anything, and it is the same text that goes into the scope document you sign.

We will

  • Enumerate what is already public, read-only, from outside your perimeter
  • Probe only the endpoints named in the scope you signed
  • Prove a path is reachable, then stop
  • Show you every finding before anyone else sees it

We will not

  • Send payloads or log in during discovery
  • Touch anything the scope document does not name
  • Invoke a write, payment, or exec tool
  • Publish anything, or name you, without written consent

The grading logic behind the discovery half is published in full.

Questions people ask first

Is it actually free?

Yes. No cost, no obligation, no requirement to buy anything afterwards. We do it because most teams do not know what their agents expose, and the fastest way to show what Guard0 does is to show you your own estate.

Is this a penetration test?

No. A pentest covers your whole application surface against a broad threat model. This is narrower and deeper: the agent layer specifically, meaning MCP servers, tool permissions, agent identity, memory, and the paths between them. It complements a pentest, it does not replace one.

Do you need access to our systems?

Not for the discovery half. We start from your domain and work the way an attacker does, from the outside. Active testing needs only the endpoints you approve, and we ask for credentials only if you want authenticated paths covered.

How long does it take?

About 5 business days from signed scope to readout. We reply to your request within one business day with times.

What if you find nothing?

Then you get that in writing, which is worth having. An A grade with the methodology attached is a defensible answer to an auditor asking how you know.

Can I see what you find before talking to anyone?

Yes. The AI Register runs the passive half of this assessment on its own, free, with no login and no sales contact. Start there if you would rather look first.

Guard0 / accountability systemOpen

What happens next

You will know what your agents expose in about 5 business days.

It costs nothing, nothing runs until you approve the scope, and the findings are yours either way. Or run the passive half yourself right now and see your grade in a minute.

Would rather talk it through? Book 30 minutes.

G0-ASSESS-00guard0.ai/free-ai-assessmentReply within one business dayScope approved in writing