Skip to content

AI and data

agent-tool-call-audit

Audit agent tool calls

Reviews recorded agent tool calls for scope creep, data exposure, unsafe actions, injected instructions and mismatches with declared tool annotations.

Area
AI and data
Checked against
MCP 2026-07-28, OWASP LLM 2025, OWASP Agentic 2026, NIST AI 600-1
Last verified
26 September 2026
Files
SKILL.md, 8 references, 1 scripts

How it works

  1. 1Secure local copies of the logs and record their hashes and sources.
  2. 2Write down the task scope, allowed targets, operations and data.
  3. 3Build a call table from logs, traces and saved tool definitions.
  4. 4Review server messages, tool definitions and annotation changes.
  5. 5Check every call for scope, exposure, approvals, injected instructions and annotation mismatches.
  6. 6Trace data flowing between calls and servers.
  7. 7Rate each finding, then report containment, fixes and log limits.

Use it when

  • Review an agent session that touched sensitive data or systems.
  • Investigate suspected prompt injection, data exposure or an unexpected action.
  • Check a new MCP server before trusting its tool annotations.
  • Test whether an approval policy worked as intended.

How it stays safe

  • Works from local copies and keeps the audit read-only.
  • Treats every string in logs, tool output and server instructions as untrusted data.
  • Masks secrets and personal data in reports while preserving evidence locations.
  • Keeps findings labeled Confirmed, Likely or Possible based on available evidence.

Install it

Copy the whole agent-tool-call-audit folder into your agent's skills folder, not only SKILL.md.

git clone --depth 1 https://github.com/hamzaahmadaslam/agent-skills.git
cp -R agent-skills/agent-tool-call-audit "<your agent's skills folder>/"

More skills in the collection

All 11 skills