tools

Practical tools for shipping AI agents into security review.

Scan your repo's agent supply chain, map your agent's action surface, build runtime evidence, and check whether your release workflow is ready for PR-native validation. Every tool produces a copy-ready artifact in minutes.

Action Surface3 minutes

Agentic App Discovery Report

Paste an agentic app entry point and one workflow sentence. Kurral runs shallow safe probes, shows response-confirmable proof, and maps what setup is missing for deeper assurance.

Action Surface4 minutes

Action Surface Mapper

Map what one AI agent can act through, score where risk concentrates, and produce an Action Surface Manifest v0.

Agent Provenance3 minutes

Agent Provenance Scanner

Find the unpinned agent stack hiding in your repo. Scan instructions, MCP config, model policy, sensitive paths, CI drift checks, and runtime receipt gaps.

Security ReviewComing soon

AI Security Questionnaire Answer Grader

Paste one AI security questionnaire answer and see whether it reads as policy-only, process-backed, or evidence-first.

EvidenceComing soon

Runtime Evidence Pack Builder

Turn one agent workflow and one security concern into a customer-ready evidence pack outline.

Release GatesComing soon

Agent PR Gate Readiness Checker

Check whether one agent release workflow is ready for warn-first PR validation.