Defense-in-Depth Control-Layer Coverage
Is your agent's safety LAYERED, or one bypass from compromise?
Every other AgentSmack meta-lens reasons from the ATTACKER side — the coverage map grades which surfaces were tested, the kill-chain min-cut gives the attacker's cheapest break, the risk register ranks findings by exploitability. This is the DEFENDER's lens. Across each kill-chain stage — entry → establish → escalate → act → exfiltrate → evade — it grades how many independent control layers (input validation, injection filter, policy enforcement, approval gate, identity/tenant isolation, egress filter, output redaction) actually held versus were absent or bypassed. It answers the question a CISO actually signs off on: is my agent resting on a single point of failure — exactly ONE control between untrusted input and a privileged or exfil action? A stage with ≥2 controls that held is layered; exactly one is a single point of failure; zero surviving controls is undefended and caps the score regardless of how every individual surface scored. The verdict is sticky — a hundred layered stages can never launder one undefended stage into a clean grade — and honest-empty: no findings reports insufficient_signal, never a fabricated “defended.” It adds no new surface and no new scorecard dimension — a pure coverage grade OVER the same findings every scan emits. Load a sample to watch the control lanes light up with no live infra.
Related read-only meta-lenses over the same findings envelope: Compensating-Control Placement (the prescriptive dual — what to deploy) · Attack-Path / Kill-Chain Correlation · Detectability / Dwell-Time (MTTD).