What is Agent Blast Radius?
Agent blast radius is the maximum credible effect that an agent can cause through its tools, credentials, data access, network reach, and chained actions. It describes potential impact, not the chance that an incident will occur.
Why it matters
Agents can combine several valid actions into a harmful result. Narrow tools, scopes, and execution boundaries limit damage from an error, prompt injection, or stolen token.
How it works
- Map the systems and actions that every tool and credential can reach.
- Test how tools can be chained and which actions can change or delete data.
- Restrict scopes, run actions in the user context, isolate execution, and require approval for high-impact actions.
Example
A support agent can read tickets and draft a reply. It cannot send, delete, or export tickets, so a malicious prompt cannot perform those actions.
Pomerium boundary
On protected Streamable HTTP Model Context Protocol routes, Pomerium can combine identity policy with tool-name policy for each request. Pomerium logs authorization decisions, and operators can add Model Context Protocol fields for the method, tool name, and parameters. This limits the access path, but it does not isolate the model or tool runtime.
Limits and non-claims
- Agent blast radius is a descriptive measure, not a standardized score.
- It changes when tools, scopes, data, or dependencies change.
- Gateway policy does not replace safe tool design, isolation, or human approval.
- Pomerium protects Model Context Protocol servers that use Streamable HTTP through a Pomerium route. It does not secure local stdio connections, the model runtime, tool code, or traffic that bypasses the route.
Evaluation checklist
- Which identities, tools, credentials, data, targets, and side effects can one agent task reach?
- Can prompt injection, goal hijack, or a compromised tool use all of that authority without approval?
- Do scope limits, budgets, independent approval, revocation, and evidence cap and reveal the damage?
Sources and further reading
- Model Context Protocol scope minimizationDocumentation
- OWASP excessive agency guidancePrimary source
- OWASP GenAI LLM Top 10 2026Primary source
- OWASP Top 10 for Agentic Applications 2026Primary source
- NIST attack surface definitionPrimary source
- Pomerium Model Context Protocol supportPomerium documentation
- Protect a Model Context Protocol serverPomerium documentation
- Pomerium MCP observabilityPomerium documentation
- Pomerium MCP referencePomerium documentation
