Skip to main content

Agent Blast Radius

Agent blast radius is the maximum credible effect that an agent can cause through its tools, credentials, data access, network reach, and chained actions.

What is Agent Blast Radius?

Agent blast radius is the maximum credible effect that an agent can cause through its tools, credentials, data access, network reach, and chained actions. It describes potential impact, not the chance that an incident will occur.

Why it matters

Agents can combine several valid actions into a harmful result. Narrow tools, scopes, and execution boundaries limit damage from an error, prompt injection, or stolen token.

How it works

  1. Map the systems and actions that every tool and credential can reach.
  2. Test how tools can be chained and which actions can change or delete data.
  3. Restrict scopes, run actions in the user context, isolate execution, and require approval for high-impact actions.

Example

A support agent can read tickets and draft a reply. It cannot send, delete, or export tickets, so a malicious prompt cannot perform those actions.

Pomerium boundary

On protected Streamable HTTP Model Context Protocol routes, Pomerium can combine identity policy with tool-name policy for each request. Pomerium logs authorization decisions, and operators can add Model Context Protocol fields for the method, tool name, and parameters. This limits the access path, but it does not isolate the model or tool runtime.

Limits and non-claims

  • Agent blast radius is a descriptive measure, not a standardized score.
  • It changes when tools, scopes, data, or dependencies change.
  • Gateway policy does not replace safe tool design, isolation, or human approval.
  • Pomerium protects Model Context Protocol servers that use Streamable HTTP through a Pomerium route. It does not secure local stdio connections, the model runtime, tool code, or traffic that bypasses the route.

Evaluation checklist

  • Which identities, tools, credentials, data, targets, and side effects can one agent task reach?
  • Can prompt injection, goal hijack, or a compromised tool use all of that authority without approval?
  • Do scope limits, budgets, independent approval, revocation, and evidence cap and reveal the damage?

Sources and further reading

Keep learning

Agentic AccessSecurity Operations and Risk

Tool Surface Area

Tool surface area is the full set of operations, inputs, external resources, and privilege effects that tools make available to an agent.

Learn this term
Agentic AccessApplication and Service Access

Per-Request Authorization

Per-request authorization evaluates each action against current identity, resource, policy, and request context immediately before enforcement.

Learn this term
Authorization and Policy

Access Control

Combine policy, reliable decision inputs, enforcement, and evidence to control actions on protected resources.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo