OWASP Agentic Excessive Agency Review
Review an agent design document for excessive tools, permissions, and autonomy before the workflow reaches production.
The full canvas, before you import it
Click any node to see its config.
Click a node to select it — same as the Heym editor; the panel shows its settings.
8 nodes · Free & source-available
OWASP Agentic Excessive Agency Review
Inspect an agent architecture document for excessive functionality, permissions, and autonomy. The workflow extracts a PDF design, normalizes the review context, and flags tool access or unattended actions that need a security decision.
What this workflow does
- AgentDesignDocument accepts a PDF architecture or threat model
- ExtractAgentDesignText converts the PDF into searchable text
- BuildAgencyReviewPacket adds the system owner and review scope
- ReviewAgentAgencyRisk evaluates tools, permissions, autonomy, and approval controls
- ExcessiveAgencyGate identifies designs needing action
- NotifyAgentSecurity sends the finding to Slack
- LogAgencyReview preserves the review summary
- AgencyReviewReceipt returns the outcome
Use cases
- OWASP LLM excessive agency reviews
- AI agent threat modeling
- Tool permission and OAuth scope audits
- Human approval design checks
Setup
Upload a PDF that lists agent goals, tools, permissions, data sources, and unattended actions. Connect an LLM credential, Slack, and DataTable. Keep final risk acceptance with the accountable security and product owners.
How to import this template
- 1Click Import → Copy JSON on this page.
- 2Open your Heym and navigate to a workflow canvas.
- 3PressCmd+V/Ctrl+V— nodes appear instantly.
- 4Add your API keys in the node config panels and click Run.
Discover more automations
- Legal & ComplianceGoverned Web Research Agent (MCP)Let an Agent fetch and summarize web pages through a Fetch MCP server routed behind the Arc Gate MCP governance proxy.
- Legal & ComplianceContract Risk Review QueueSummarize pasted contract text, flag risky clauses, and send review-needed items to Slack for legal follow-up.
- Legal & ComplianceContract Renewal & Expiry TrackerScan a contract register on a schedule, flag agreements nearing renewal or auto-renew notice deadlines, and alert owners in Slack.
- Legal & ComplianceGDPR Data Subject Request (DSAR) RouterClassify an incoming data subject request, compute the statutory deadline, and escalate sensitive cases to the DPO in Slack.
- Legal & CompliancePII Redactor (Agent Skill)An agent runs a bundled Python skill that redacts emails, phone numbers, card numbers, and SSNs from text before it is shared.
- Legal & ComplianceNDA Generator from IntakeTurn a few details about two parties and a purpose into a clean, structured NDA draft for legal review.
- Legal & ComplianceContract Obligation & Deadline ExtractorPaste contract text and extract obligations, owners, key dates, and renewal terms into a clean structured list.
- Legal & ComplianceCompliance Checklist GeneratorGenerate a tailored compliance checklist for a framework like SOC 2, GDPR, or HIPAA, scoped to your business context.
- Legal & ComplianceCease and Desist Letter (Agent Skill, PDF)An agent drafts a cease and desist letter, then a bundled Python skill renders it into a formatted, downloadable PDF.
- Legal & ComplianceDemand Letter Generator (Agent Skill, PDF)An agent drafts a formal payment demand letter; a bundled Python skill totals the amounts owed and renders a downloadable PDF.
- Legal & CompliancePrivacy Policy Generator (Agent Skill, PDF)An agent drafts a GDPR and CCPA aware privacy policy; a bundled Python skill renders the numbered sections into a downloadable PDF.
- Legal & ComplianceEU AI Act Article 50 Transparency LedgerReview synthetic content disclosures, route missing transparency controls, and keep an evidence ledger for Article 50 operations.