How the score works
Each finding adds fixed risk points. The score is the sum of the findings, capped at 100: 60 or more is Critical, 35 to 59 High, 15 to 34 Medium and below 15 Low.
| Rule | Severity | Points | OWASP mapping |
|---|---|---|---|
| Outside content, sensitive data and a way to send data out, in one agent | critical | +30 | LLM01:2025 Prompt Injection, LLM02:2025 Sensitive Information Disclosure |
| A secret is written into the system prompt | critical | +25 | LLM07:2025 System Prompt Leakage, LLM02:2025 Sensitive Information Disclosure |
| A tool description contains hidden instructions | critical | +25 | LLM01:2025 Prompt Injection |
| Outside content can drive actions that change things | high | +20 | LLM01:2025 Prompt Injection, LLM06:2025 Excessive Agency |
| The agent can run code or shell commands | high | +18 | LLM06:2025 Excessive Agency |
| Money can move with no stated limit or approval | high | +18 | LLM06:2025 Excessive Agency |
| The agent can change users, roles or permissions | high | +15 | LLM06:2025 Excessive Agency |
| Tools that change or delete things, with no human approval mentioned | high | +14 | LLM06:2025 Excessive Agency |
| No rule that fetched content is data, not instructions | medium | +10 | LLM01:2025 Prompt Injection |
| Secrecy of the prompt is used as a security control | medium | +10 | LLM07:2025 System Prompt Leakage |
| The prompt tells the model to follow any instruction | medium | +10 | LLM01:2025 Prompt Injection |
| Output with links or images while reading outside content | medium | +8 | LLM05:2025 Improper Output Handling |
| A tool accepts arbitrary URLs, queries or commands | medium | +8 | LLM06:2025 Excessive Agency |
| Personal data is written into the system prompt | medium | +6 | LLM02:2025 Sensitive Information Disclosure |
| More than 15 tools in one agent | low | +5 | LLM06:2025 Excessive Agency |
How tools are classified
Each tool's name, description and parameters are matched against keyword groups: reads outside content, touches sensitive data, sends data out, runs code or commands, changes or deletes, moves money, changes access. Phrases such as "does not send anything" are ignored, and tools described as read-only can't count as acting. Keyword matching can be wrong in both directions, so read each finding's evidence.