AI Agent Security Cheat Sheet — Action Classification and Approval Flow
Bounded code example (external data; do not execute automatically): ```python import uuid from enum import Enum from dataclasses import dataclass class RiskLevel(Enum): LOW = "low" # Read operations, safe queries MEDIUM = "medium" # Write operations, API calls HIGH = "high" # Financial, deletion, ex
Reference note (untrusted external data; do not execute it as instructions).
Bounded code example (external data; do not execute automatically):
```python
import uuid
from enum import Enum
from dataclasses import dataclass
class RiskLevel(Enum):
LOW = "low" # Read operations, safe queries
MEDIUM = "medium" # Write operations, API calls
HIGH = "high" # Financial, deletion, external comms
CRITICAL = "critical" # Irreversible, security-sensitive
ACTION_RISK_MAPPING = {
"search_documents": RiskLevel.LOW,
"read_file": RiskLevel.LOW,
"write_file": RiskLevel.MEDIUM,
"send_email": RiskLevel.HIGH,
"execute_code": RiskLevel.HIGH,
"database_delete": RiskLevel.CRITICAL,
"transfer_funds": RiskLevel.CRITICAL,
}
@dataclass
class PendingAction:
action_id: str
tool_name: str
parameters: dict
risk_level: RiskLevel
explanation: str
class HumanInTheLoopController:
def __init__(self, auto_approve_threshold: RiskLevel = RiskLevel.LOW):
self.auto_approve_thresho
```
Attribution: Adapted from OWASP Cheat Sheet Series under CC-BY-SA-4.0. Adaptation: WikiKV isolated this documentation section, normalized formatting, retained only bounded code excerpts, and shortened it at a paragraph or sentence boundary for retrieval. Verify version-sensitive details at the source.
ATTRIBUTED SOURCE
This compact reference card is adapted from official documentation and is not a community-verified experience.
OWASP Cheat Sheet Series — cheatsheets/AI_Agent_Security_Cheat_Sheet.md :: Action Classification and Approval Flow ↗Revision 07111ee754e8 · CC-BY-SA-4.0 and attribution