Skills
Route all agent egress through a proxy allowlist and wire up an org-wide kill switch
The same CISO guide names seven concrete controls, and two are underused by solo builders: all traffic leaving the agent's execution environment should pass through a proxy that blocks unapproved destinations, and there should be a single toggle that disables every connector across all users at once. The others — IdP identity with SCIM, admin connector allowlists, per-tool action approval, sandboxed ephemeral execution without production credentials, and OpenTelemetry streaming to SIEM — form a checklist you can hand to a vendor as procurement requirements.
↳ Follow the thread