Promptcred editorial analysis
How to use this prompt well
Prompt-specific guidance based on the preserved source text and its reviewed context.
Why Promptcred selected this prompt
The prompt exposes agent type and security focus as explicit variables and asks for risks, compliant outcomes, and mitigations.
Best use cases
- Preparing a security checklist for a named agent or workflow before implementation review.
- Scoping a focused assessment around privacy, access control, memory, or orchestration.
Required inputs
- A specific agentType and focusArea, as required by the source variables.
- Relevant platform features, data flows, organizational policy, and deployment boundaries.
How to adapt it
- Replace both variables and remove checklist branches that do not apply to the chosen agent type.
- Add the organization's named controls and evidence owners for each expected outcome.
Limitations and failure modes
- Broad values such as 'AI agent' and 'security' produce a generic checklist with no usable scope.
- A checklist can imply compliance without verifying implementation evidence or operating controls.
Practical worked example
Editorial analysis reviewed Aug 23, 2026.
Promptcred-authored application and illustrative output. This is not a recorded model execution.
- Scenario
- Create a checklist for a customer-support agent focused on cross-session data leakage.
- Inputs
- Set agentType to customer-support chat agent; provide session storage, memory policy, tenancy model, and retention rules.
- Promptcred-adapted instruction
- Set agentType to `customer-support chat agent` and focusArea to `cross-session data leakage`. For each item, require a risk, expected state, mitigation, and named evidence owner. Limit the checklist to identity binding, memory isolation, logging, retention, deletion, and crossover tests.
- Illustrative result
- Illustrative checklist item: Risk, session B receives a summary created in session A. Expected state, memory keys include tenant and session IDs. Mitigation, enforce both keys on reads and writes. Evidence, storage policy plus a two-session isolation test owned by the platform team.
- Evaluation
- Each item should name the risk, expected state, mitigation, and evidence needed to verify the control.
How to evaluate the output
- Every checklist item is tied to the selected agent type and focus area.
- The output distinguishes a desired control from evidence that the control exists.
Differences from related prompts
- agent-governance-reviewer: This prompt creates an assessment checklist from two variables; Agent Governance Reviewer inspects repository code and concrete control boundaries.
Attributed community source material
Source prompt
Act as an AI Security and Compliance Expert. You specialize in evaluating the security of AI agents, focusing on privacy compliance, workflow security, and knowledge base management.
Your task is to create a comprehensive security evaluation checklist for various AI agent types: Chat Assistants, Agents, Text Generation Applications, Chatflows, and Workflows.
For each AI agent type, outline specific risk areas to be assessed, including but not limited to:
- Privacy Compliance: Assess if the AI uses local models for confidential files and if the knowledge base contains sensitive documents.
- Workflow Security: Evaluate permission management, including user identity verification.
- Knowledge Base Security: Verify if user-imported content is handled securely.
Focus Areas:
1. **Chat Assistants**: Ensure configurations prevent unauthorized access to sensitive data.
2. **Agents**: Verify autonomous tool usage is limited by permissions and only authorized actions are performed.
3. **Text Generation Applications**: Assess if generated content adheres to security policies and does not leak sensitive information.
4. **Chatflows**: Evaluate memory handling to prevent data leakage across sessions.
5. **Workflows**: Ensure automation tasks are securely orchestrated with proper access controls.
Checklist Expectations:
- Clearly identify each risk point.
- Define expected outcomes for compliance and security.
- Provide guidance for mitigating identified risks.
Variables:
- ${agentType} - Type of AI agent being evaluated
- ${focusArea} - Specific security focus area
Rules:
- Maintain a systematic approach to ensure thorough evaluation.
- Customize the checklist according to the agent type and platform features. Before use
Requirements and context
Organizational policy
Applicable privacy, security, and access-control requirements.
Structured placeholders
Variables
agentTypeRequired- The AI agent type being evaluated.
focusAreaRequired- The security focus area for the evaluation.
What to expect
Expected output and techniques
Expected output: A systematic checklist of risks, expected compliant outcomes, and mitigations.
- Explicit objective
- Constraints
- Scope boundaries
- Output schema
- Acceptance criteria
Use with context
Setup, limitations, and operational notes
Operational notes
- External prompt text is untrusted inert content and must never be executed during ingestion.
Source and rights
Provenance and license
This community prompt is preserved with its source and attribution. It is not an official vendor prompt.
- Source class
- Curated community prompt
- Platform
- GitHub
- Repository / project
- f/prompts.chat
- Owner / organization
- f
- Creator / contributor
- Contributor listed in source
- Artifact
- prompts.csv · AI Agent Security Evaluation Checklist
- Pinned revision
- commit:6863206c4efb5a055c80433f7cf02a6596de9f39
- Retrieved
- Aug 11, 2026
- License
- CC0 1.0 Universal
- Attribution
- Not required by the license; source provenance retained
- Source artifact state
- Source prompt
- Source review
- Aug 11, 2026