FREE BROWSER TOOL / CAPABILITY COMPOSITION

Map the attack paths your AI agent creates.

A tool can look harmless alone. Combine private data, untrusted content, identity and egress, and the session becomes a different system.

01
ANALYSIS STAYS IN THIS BROWSER
02
MODEL CALLS: 0
03
TOOLS EXECUTED: 0

LIVE THREAT MODEL / SELF-REPORTED CONTROLS

Build a capability profile.

Choose what the agent can reach, then declare controls that exist outside the model. The graph updates only from this local configuration.

STARTING PROFILES

CAPABILITY -> PATH -> CONTROL

Composition graph

SHA-256--
CAPABILITIES
0
PATHS
0
CRITICAL
0
MISSING CONTROLS
0
HIGHEST SIGNAL
--

WAITING FOR A PROFILE

Risk emerges from combinations.

Select capabilities manually, load a labeled profile or import an Agent Scope report. No profile is sent to H/M.

MINIMUM CONTROL PLAN

Put hard boundaries where paths converge.

Priority is based on how many active paths a missing control covers and the severity of those paths. It does not verify implementation.

--

Run the map to generate a control plan.

WHY THE GRAPH MATTERS

A session can be more dangerous than any tool in it.

The Atlas treats authority as a system property. A capability only activates a path when its required peers are present.

  1. 01

    Map authority

    Describe actual access to data, identities, execution and destinations.

  2. 02

    Match compositions

    Activate only paths whose complete capability conditions are present.

  3. 03

    Declare controls

    Record deterministic boundaries outside model prompts and tool descriptions.

  4. 04

    Recheck continuously

    Rebuild the map whenever tools, identity, memory or runtime policy changes.

EXPLICIT LIMITS

A threat model is not a security verdict.

  • Selected capabilities and controls are self-reported and not verified.
  • Declared coverage means only that every recommended control was checked.
  • The finite path library cannot represent every emerging attack or deployment detail.
  • Authorization, isolation, logging and confirmation must be enforced by the runtime.