Customer Support Automation
ATC-AGT-0007731
88
critical risk
Identity
Who owns it, and what it is for
- Declared purpose
- Undeclared. Discovered from model API traffic and an unattributed key.
- Business owner
- Unassigned — nobody is accountable for this agent
- Technical owner
- Unassigned
- Provider and model
- Anthropic · unresolved
- Framework
- Unknown
- Environment
- unknown
- Data classes reached
- Confidential, PII
- Last activity
- 11 minutes ago
Risk
Why the score is 88
Every point is accounted for. Remove a factor and the score moves by exactly that much.
- +20
Compliance
No owner of record. Nobody is accountable for it
- +18
Data
Reaches customer PII across Salesforce and Gmail
- +15
Privilege
Holds export and send rights it has never been approved for
- +12
Action
Can send mail to customers unattended
- +10
Model
Model and version could not be resolved from traffic
- +13
External exposure
Sends outbound mail from an unmanaged credential
- 88Total
Access
What it may do, action by action
Permissions are held at the level of the action, so reading a record and changing its banking details are separate grants that can be decided separately.
- read_contactSalesforceL0 ReadGranted
- update_contactSalesforceL2 Execute, low riskGranted
- export_contactsSalesforceL3 SensitiveGranted
- send_emailGmailL2 Execute, low riskGranted
Dependencies
MCP servers it is bound to
None registered. For an agent discovered from traffic rather than declared, that is an absence of evidence rather than evidence of absence.
Execution identity
What it authenticates as
An agent does not reach anything by itself. It runs as a machine identity, and that identity is what actually holds the credential — so the agent's permissions are only ever a subset of what this can do.
- Salesforce Integration Account66
ATC-MID-0003901 · Salesforce
Client secretShared with 1 other agent. An action taken through this credential cannot be attributed to one of them.
Supply chain
Bill of materials
What this agent is assembled from. It is also the answer to the blast-radius question when one of these is compromised.
Model
Framework
Tools
MCP servers
None
Databases
None
Packages
Runtime
Decisions taken on its behalf
Every governed action produces one of these, and each records the rule that decided it.
- 09:41:02read_contactsalesforce:bulkAllowed
rule: observe-only · not yet enforced
- 09:41:40export_contactssalesforce:bulkAllowed
rule: observe-only · not yet enforced