FREE BROWSER TOOL / CAPABILITY COMPOSITION
Map the attack paths your AI agent creates.
A tool can look harmless alone. Combine private data, untrusted content, identity and egress, and the session becomes a different system.
- 01
- ANALYSIS STAYS IN THIS BROWSER
- 02
- MODEL CALLS: 0
- 03
- TOOLS EXECUTED: 0
LIVE THREAT MODEL / SELF-REPORTED CONTROLS
Build a capability profile.
Choose what the agent can reach, then declare controls that exist outside the model. The graph updates only from this local configuration.
SYNTHETIC STARTING PROFILEFor demonstration only and counted separately from manual maps.
CAPABILITY -> PATH -> CONTROL
Composition graph
--- CAPABILITIES
- 0
- PATHS
- 0
- CRITICAL
- 0
- MISSING CONTROLS
- 0
- HIGHEST SIGNAL
- --
WAITING FOR A PROFILE
Risk emerges from combinations.
Select capabilities manually, load a labeled profile or import an Agent Scope report. No profile is sent to H/M.
DETERMINISTIC PATH MATCHES
Active attack paths
MINIMUM CONTROL PLAN
Put hard boundaries where paths converge.
Priority is based on how many active paths a missing control covers and the severity of those paths. It does not verify implementation.
Run the map to generate a control plan.
WHY THE GRAPH MATTERS
A session can be more dangerous than any tool in it.
The Atlas treats authority as a system property. A capability only activates a path when its required peers are present.
- 01
Map authority
Describe actual access to data, identities, execution and destinations.
- 02
Match compositions
Activate only paths whose complete capability conditions are present.
- 03
Declare controls
Record deterministic boundaries outside model prompts and tool descriptions.
- 04
Recheck continuously
Rebuild the map whenever tools, identity, memory or runtime policy changes.
EXPLICIT LIMITS
A threat model is not a security verdict.
- Selected capabilities and controls are self-reported and not verified.
- Declared coverage means only that every recommended control was checked.
- The finite path library cannot represent every emerging attack or deployment detail.
- Authorization, isolation, logging and confirmation must be enforced by the runtime.