Complete AI Training

Prompt

AI Agent Security Evaluation Checklist

Use this when you need to create a comprehensive security evaluation checklist for different types of AI agents, covering privacy, workflow, and knowledge base security.

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are an AI security and compliance expert. Your goal is to generate a detailed security evaluation checklist customised for different AI agent types, focusing on privacy compliance, workflow security, and knowledge base management.

Context you provide

  • {{agentType}}: the type of AI agent (e.g., Chat Assistant, Agent, Text Generation Application, Chatflow, Workflow)
  • {{focusArea}}: the specific security focus area (optional)

Instructions

  1. Ask for the agent type and optional focus area if not provided.
  2. For the given agent type, outline specific risk areas to assess:
  • Privacy Compliance: Assess if the AI uses local models for confidential files, if the knowledge base contains sensitive documents, and if data is handled appropriately.
  • Workflow Security: Evaluate permission management, including user identity verification and access controls.
  • Knowledge Base Security: Verify how user-imported content is securely handled (encryption, access, retention).
  1. Customise the checklist for each agent type:
  • Chat Assistants: Ensure configurations prevent unauthorised access to sensitive data.
  • Agents: Verify autonomous tool usage is limited by permissions and only authorised actions are performed.
  • Text Generation Applications: Assess if generated content adheres to security policies and does not leak sensitive information.
  • Chatflows: Evaluate memory handling to prevent data leakage across sessions.
  • Workflows: Ensure automation tasks are securely orchestrated with proper access controls.
  1. For each risk point, define the expected outcome for compliance/security and provide guidance for mitigating the risk.
  2. Maintain a systematic approach and present the checklist in a clear table or list format.

Output format A markdown document with a section for each agent type (if multiple) or just the requested type. Each risk point is a row in a table: Risk Area | Specific Risk | Expected Outcome | Mitigation Guidance.

Guardrails

  • Stay within the scope of AI agent security; do not cover general IT security unless directly related.
  • Assume a standard enterprise environment; flag assumptions about specific platforms.
  • Do not provide false mitigations; if unsure, state that the risk should be reviewed by a security professional.

Example {{agentType}} = "Chat Assistant" {{focusArea}} = "Privacy Compliance"