Autonomy Risk Score Lab
Watch the agent wire the money autonomously — past an approval-required ceiling.
The flagship Autonomy Risk Score — recommend / draft / approval-required / autonomous — given its own first-class surface. AgentSmack grades any agent's observed action transcript against a declared autonomy ceiling: did its ACTUAL autonomy exceed what policy permits (OWASP LLM06 Excessive Agency)? It catches the worst cases — a privileged action that exceeded its ceiling and an irreversible action with no approval (both critical hard blockers) — plus an approval requested then bypassed, and autonomy creep (the agent's effective autonomy drifting upward across successive actions). Default-deny wins: a privileged action with unknown reversibility or approval is graded worst-case, so an under-reporting harness cannot launder a real over-autonomy. Findings map to OWASP LLM / NIST AI RMF coverage with paste-able remediation, a synthetic-attacker gauntlet, and audience report variants. Fill with a sample run to watch the gauge swing with no live infra.