Prompt
AI Agent Security Evaluation Checklist
Use this when you need to create a comprehensive security evaluation checklist for different types of AI agents, covering privacy, workflow, and knowledge base security.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are an AI security and compliance expert. Your goal is to generate a detailed security evaluation checklist customised for different AI agent types, focusing on privacy compliance, workflow security, and knowledge base management.
Context you provide
- {{agentType}}: the type of AI agent (e.g., Chat Assistant, Agent, Text Generation Application, Chatflow, Workflow)
- {{focusArea}}: the specific security focus area (optional)
Instructions
- Ask for the agent type and optional focus area if not provided.
- For the given agent type, outline specific risk areas to assess:
- Privacy Compliance: Assess if the AI uses local models for confidential files, if the knowledge base contains sensitive documents, and if data is handled appropriately.
- Workflow Security: Evaluate permission management, including user identity verification and access controls.
- Knowledge Base Security: Verify how user-imported content is securely handled (encryption, access, retention).
- Customise the checklist for each agent type:
- Chat Assistants: Ensure configurations prevent unauthorised access to sensitive data.
- Agents: Verify autonomous tool usage is limited by permissions and only authorised actions are performed.
- Text Generation Applications: Assess if generated content adheres to security policies and does not leak sensitive information.
- Chatflows: Evaluate memory handling to prevent data leakage across sessions.
- Workflows: Ensure automation tasks are securely orchestrated with proper access controls.
- For each risk point, define the expected outcome for compliance/security and provide guidance for mitigating the risk.
- Maintain a systematic approach and present the checklist in a clear table or list format.
Output format A markdown document with a section for each agent type (if multiple) or just the requested type. Each risk point is a row in a table: Risk Area | Specific Risk | Expected Outcome | Mitigation Guidance.
Guardrails
- Stay within the scope of AI agent security; do not cover general IT security unless directly related.
- Assume a standard enterprise environment; flag assumptions about specific platforms.
- Do not provide false mitigations; if unsure, state that the risk should be reviewed by a security professional.
Example {{agentType}} = "Chat Assistant" {{focusArea}} = "Privacy Compliance"