CrawlCheck

Glossary · Security and privacy

Excessive agency

Granting an agent more tools, permissions, autonomy, or action scope than needed. Accuracy improvements do not compensate for avoidable blast radius.

Terms this definition uses

Accuracy

Security and privacy

Where an agent, a tool or a page can be turned against its operator, and the controls that limit the damage without proving safety.

Indirect prompt injection · Direct prompt injection · Jailbreak · Data exfiltration · Sensitive information disclosure · Secret leakage · Insecure output handling · Least privilege · Trust boundary · Input validation · Output validation · Allowlist · Denylist · SSRF · RCE · Credential scope · OAuth scope · API key · Bearer token · mTLS · Rate-limit policy · Audit log · PII · Data minimization · Purpose limitation · Retention period · Data residency · Tenant isolation · Threat model

Insecure output handling  ·  Least privilege

See it in the full glossary · 579 terms across 19 areas. Scan a site to see which of these apply to it.