AgentHive Inc. — Operator-dense, defense-only guidance for securing AI agents that use tools, MCP servers, and credentials.
Product: Bot Lock · Companion: Field Kit ($49 one-time) · Version: 2.1
Audience: Platform engineers, security operators, SRE/on-call, and agent owners who run production or staging agent systems they are authorized to control.

This playbook designs, reviews, and verifies agent control planes. It does not provide exploit PoCs, attack payloads, bypass recipes, or unauthorized testing procedures. Authorized self-assessment themes align with Bot Lock Check. Red-team exploit reproduction is out of scope.

Get the full playbook

Chapters 2–13 and the appendices, plus the Field Kit policy YAML templates (deny-by-default tools, MCP allowlist, secrets, kill switch).

Get Field Kit · $49 one-time Get Pro · $149 one-time

Stripe checkout. After payment you land on the full playbook. Compare Field Kit and Pro · Run the free Check first

Table of contents

  1. Why this exists
  2. Core principles
  3. Threat model checklist
  4. Weighted control catalog
  5. Policy how-to (Field Kit YAML) — includes OAuth/token and exfil/I/O how-tos
  6. Kill-switch runbook
  7. Authorized verification playbook — includes drills V1–V10
  8. Anti-patterns
  9. 30-day adoption / rollout plan
  10. Sample audit event shapes
  11. Incident vignettes
  12. Honest limits
  13. Product map and file map
  14. Appendices — glossary, operator card, implementation notes, tabletops, Check mapping, FAQ, weekly audit ritual, on-call card, procurement / honesty FAQ

1. Why this exists

AI agents that read untrusted content and call tools turn text into actions. That is the product value and the security problem in the same sentence. A support agent that can open tickets, draft replies, and look up customer records is useful until a poisoned email, a malicious PDF comment, or a compromised MCP plugin rewrites its intent and those same tools become the blast radius.

Operators are already shipping agents with:

Industry educational sources (weighted themes from English operator-facing material, Mar–Sep 2026) repeatedly surface the same failure modes. Bot Lock Check and this Field Kit playbook weight controls by how often those themes appear in that research set:

Weight Theme Operator focus
16/20 Prompt injection / jailbreak Untrusted text as executable influence
16/20 Logging / monitoring / audit Assume breach; instrument everything
12/20 Least privilege / IAM Task-scoped, time-bound access
11/20 Excessive agency Cap autonomy and blast radius
11/20 Agent tool abuse Tools are the new attack surface
11/20 Supply chain / MCP / plugins Untrusted by default
10/20 Secrets management Vaults, not prompts
9/20 Data exfiltration DLP + egress controls
9/20 Guardrails / I/O filtering Defense outside the model
9/20 Token delegation / OAuth No confused-deputy passthrough

Who this playbook is for

Get the full playbook

Chapters 2–13 and the appendices, plus the Field Kit policy YAML templates (deny-by-default tools, MCP allowlist, secrets, kill switch).

Get Field Kit · $49 one-time Get Pro · $149 one-time

Stripe checkout. After payment you land on the full playbook. Compare Field Kit and Pro · Run the free Check first

AgentHive Inc·About Daniel Graham·Consult·First Deploy·AI Nexus 360·Infrastructure·Flick·JobProof·IndexMe·Bot Lock

Built by Daniel Graham, founder of AgentHive Inc · 25 years in enterprise IT and telecom · Palm Coast, FL · 320-335-6186 · daniel@agenthiveinc.com