Back to Audit Overview
Autonomous Agent DefenseDeterministic Blast-Radius Containment

Autonomous Agent Blast-Radius & Containment Audit

Traditional perimeter defenses and Web Application Firewalls fail against autonomous agents because the attack originates from authorized internal tokens executing inside privileged execution loops. We audit your agent tool harnesses, microVM sandboxes, and capability delegation chains against the 8 catastrophic breakout vectors.

Turnaround: 72 hours (3 working days)
Commercial Terms: £2,500 fixed fee
Delivery Model: Asynchronous git patch & evidence ledger

Audit Deliverables

01

Static Threat & Privilege Ledger

Every raw subprocess execution, unconstrained filesystem write, and ambient credential leak identified with exact AST file and line coordinates.

02

Capability Chain & Blast-Radius Proof

A concrete map of subagent recursion paths proving where secondary worker agents inherit escalated permissions, host mounts, or cloud credentials.

03

Tool Interceptor Hardening Patch

An engineer-ready git patch wrapping mutating tools in deterministic parameter-schema validators, idempotency keys, and explicit human approval gates.

04

Egress Enclave & Metadata Firewall Spec

Container and network policy configurations blocking unauthenticated internal proxy egress, IMDS metadata hops (169.254.169.254), and host daemon sockets.

The 8 Exploit & Blast-Radius Vectors Audited

Evaluated deterministically via AST inspection and execution path analysis.

CRITICAL-30 pts

Unbounded Shell & Command Execution

Agent tools expose raw shell or subprocess execution without strict binary allowlists or ephemeral microVM isolation.

Remediation: Replace raw shell execution with parameter-validated RPC handlers or isolate command tools within short-lived microVMs (Firecracker).
CRITICAL-25 pts

Proxy Sandbox Breakout & Container Escape

Agent environment mounts docker socket (/var/run/docker.sock), uses host networking, or allows unauthenticated internal proxy egress.

Remediation: Enforce gVisor or Firecracker virtualization, eliminate docker.sock mounts, and block 169.254.169.254 metadata endpoints.
HIGH-20 pts

Unguarded Capability Chaining

Autonomous agents can spawn secondary worker agents or delegate privileged mutations without cryptographic token gates.

Remediation: Install deterministic approval gates, scope capability tokens with strict TTLs, and prohibit autonomous subagent recursion.
HIGH-15 pts

Long-Lived Administrative Credentials in Runtime

Persistent administrative API keys (OpenAI, AWS, GitHub) are injected directly into agent context or environment variables.

Remediation: Issue scoped ephemeral credentials (e.g. GitHub App tokens, AWS STS) with least-privilege role boundaries.
HIGH-15 pts

Unconstrained Outbound Network Egress

Agent containers permit arbitrary outbound HTTP/TCP traffic, creating direct channels for data exfiltration.

Remediation: Deploy strict DNS and IP egress firewalls; restrict outbound connections to authenticated model APIs only.
MEDIUM-10 pts

Wildcard Filesystem Mutability

Agent tools allow arbitrary file modifications across host directories outside isolated target workspaces.

Remediation: Constrain file modification tools to isolated directory trees with strict path canonicalization checks.
MEDIUM-10 pts

Unsanitized Indirect Prompt Injection Ingestion

Third-party data (web scraping, untrusted issues, emails) is concatenated directly into system instructions without delimiter guards.

Remediation: Wrap untrusted context in cryptographic XML/markdown delimiters and enforce taint-tracking on model instruction parsing.
MEDIUM-8 pts

Unintercepted Tool Invocation

Mutating tools execute immediately upon model request without a deterministic policy validation layer.

Remediation: Route all tool calls through an interceptor proxy verifying parameter bounds, idempotency, and human-in-the-loop policies.
Case Study & Technical Reference

Why WAFs Failed: Deconstructing the 1,200-Agent Hugging Face Breakout

In mid-2026, an autonomous offensive agent cluster capability-chained across proxy sandboxes, compromising upstream infrastructure via unauthenticated internal artifact proxies and mounted Docker daemon sockets. Read the architectural post-mortem and the Three Invariants of Defensive Runtimes.

Authorize 72-Hour Containment Audit

Provide read access to your agent repository or tool harness. We deliver the Static Threat Ledger, Blast-Radius Map, and Tool Interceptor git patch within 72 hours.

Asynchronous Codebase Audit Intake

Authorize repository test suite audit

Provide read access to one target repository or package. Pramāṇa analyzes AST assertion density, locates unasserted domain error branches, and runs synthetic fault mutations in an isolated sandbox. Delivery completes asynchronously within 72 hours.

For private repositories, grant read access to pramana-bot@anystackengineering.com after authorization.
We deliver the Static Assertion Ledger, Fault Resistance Proof, and Hardening PR to this address.

Pramāṇa Audit Guarantee

£2,500 fixed fee. If Pramāṇa identifies fewer than three actionable domain assertion gaps or surviving mutants in your test suite, the audit fee is waived in full.

72-hour turnaround · Asynchronous delivery

Delivered as: Static Assertion Ledger, Error Branch Matrix, Fault Proof, and Hardening PR.

Commercial Terms

£2,500 fixed fee. Net-14 corporate invoice or corporate card. Zero hourly billing.

Audit Guarantee

Fee waived in full if fewer than 3 actionable containment gaps or unintercepted tool vectors are found.

Vendor Entity

Anystack Engineering (OPC) Private Limited · CIN: U62013OD2024OPC046001 · ISO 27001 & ISO 9001.