Autonomous Agent Function Calling Security Governance Evaluation
Evaluate API security, sandboxing, and token permissions for client-facing autonomous agent tool ecosystems.
Use this template to generate a client security audit report assessing function-calling safety, credential delegation, and sandbox isolation prior to connecting agents to enterprise backends.
Role: Principal AI Security Consultant and Enterprise Governance Lead.
Context
- Client Security Lead: {{client_security_lead}}
- Target Organization: {{client_organization}}
- Inspected Agent Identifier: {{target_agent_id}}
- Exposed API Endpoints: {{exposed_api_endpoints}}
- Token Authorization Framework: {{token_authorization_model}}
- Isolation Environment: {{sandbox_runtime_environment}}
Task
Compile a comprehensive Function-Calling Security Governance Report for {{client_security_lead}} at {{client_organization}}, evaluating prompt-injection resilience, API permission scoping, and execution containment for {{target_agent_id}}.
Method
- Enumerate the attack surface presented by {{exposed_api_endpoints}} when invoked autonomously.
- Assess vulnerability to indirect prompt injection and malicious argument override via tool inputs.
- Review the least-privilege enforcement mechanisms provided by {{token_authorization_model}}.
- Audit runtime isolation and network egress policies inside {{sandbox_runtime_environment}}.
- Evaluate deterministic output parsing to prevent arbitrary code execution during payload handling.
- Formulate required guardrails for destructive tool actions, including mandatory human confirmation gates.
- Define continuous audit logging and anomaly detection requirements for anomalous tool-call spikes.
Constraints
- MUST classify every discovered risk according to standard enterprise severity levels (Critical, High, Medium, Low).
- MUST NOT recommend full tool autonomy for high-risk write, delete, or fund-transfer operations.
- MUST ground all remediation guidance in the specific context of {{token_authorization_model}} and {{sandbox_runtime_environment}}.
- Keep recommendations practical, actionable, and aligned with standard compliance frameworks.
Output format
Generate a formal security assessment structured into:
- Threat Horizon & Executive Summary (max 120 words)
- Tool-Calling Vulnerability & Attack Surface Matrix (table: Endpoint, Threat Vector, Severity, Mitigation)
- Sandbox Isolation & Token Delegation Review (detailed narrative analysis)
- Security Baseline Checklist (bulleted list of mandatory fixes before client deployment)
Self-review
- Verify that each endpoint listed in {{exposed_api_endpoints}} is accounted for in the threat analysis.
- Confirm that the sandbox evaluation specifically references {{sandbox_runtime_environment}} limitations.
- Ensure all human-in-the-loop triggers for destructive functions are clearly specified.
Explicit role, a named task, and discrete steps the model can follow.
Background, inputs and variables the model needs before it starts.
Hard boundaries — what the model must and must not do.
A named, field-level shape for the response.
Ordered work items that force analysis before an answer.
Length and structure that travel across frontier models.
Signal density — instruction weight without padding.
Documented variables so the scaffold adapts to new inputs.
Quality bar, assumptions and behaviour when inputs are thin.
How much real usage the template has behind it.