AI agent threat modeling

Know what your agents can expose.

Helmwart imports real agent configs and finds the risky combinations: outside content, sensitive data, and tools that can send it out.

Free during beta. No payment required.

live canvas · MCP tool server2 trifecta findings
The Helmwart canvas showing the MCP-based tool server template. The header counts 20 open findings, 2 trifecta findings, 2 zero-trust violations and 36 defence-in-depth gaps. Eight nodes sit in four trust zones: client agents, MCP server, external systems and supporting memory. The Analyst panel for Client Agent A reads: this agent can reach private data, untrusted content and an outbound network simultaneously; per Simon Willison and EchoLeak, CVE-2025-32711, this is the structural precondition that turns prompt injection into exfiltration; break any one leg to break the trifecta.The Helmwart canvas showing the MCP-based tool server template. The header counts 20 open findings, 2 trifecta findings, 2 zero-trust violations and 36 defence-in-depth gaps. Eight nodes sit in four trust zones: client agents, MCP server, external systems and supporting memory. The Analyst panel for Client Agent A reads: this agent can reach private data, untrusted content and an outbound network simultaneously; per Simon Willison and EchoLeak, CVE-2025-32711, this is the structural precondition that turns prompt injection into exfiltration; break any one leg to break the trifecta.
Real Helmwart canvas from the MCP tool-server template. Client Agent A is flagged because one route touches memory, third-party tool content, and external APIs.
Reads actual configs

MCP, n8n, LangGraph, Bedrock, Foundry and 15 more import formats.

Finds exposure routes

Uses 51 agent threat entries across tools, memory, data and workflow authority.

Gives concrete fixes

68 mitigations written as controls your team can add or test.

Prepares the review

Exports findings and evidence for security, governance and audit conversations.

Prompt injection becomes a leak when private data and outbound tools meet.

Reviewing prompts alone misses the important question. Can the same agent take outside text, reach private data, and use a tool that sends data somewhere else?

Helmwart findingopen risk
01Outside content

User input, retrieved pages, tool descriptions, third-party responses.

02Sensitive data

Memory, files, customer records, prompts, internal state.

03Outbound tool

APIs, webhooks, ticketing systems, network calls.

If one agent can combine all three, Helmwart opens a concrete finding with the control your team can add or test.

The answers teams need before approval.

Security, engineering, and governance get one shared threat model instead of separate screenshots, opinions, and last-minute documents.

Security asks

What can this agent reach?

Helmwart shows the reachable data, tools, memory and external channels from the real setup.

Engineering asks

Where do we change it?

Each finding points to the agent, tool, memory store or connection that creates the exposure.

Governance asks

What proof can we hand over?

Export findings, mitigations and review evidence instead of rebuilding the story in a doc.

Where is the threat model for this agent system?

That question shows up in customer security reviews, AI governance gates, SOC 2 work, and incident follow-up. Helmwart gives you the answer before it becomes a blocker.

One workflow from setup to evidence.

Start from a real system, open the risky route, attach the mitigation, and export the review answer.

The Helmwart template library: a grid of architecture templates including Blank canvas, Consumer Fintech and Personal RAG assistant, each card showing agent count, edge count, findings count and trifecta count.The Helmwart template library: a grid of architecture templates including Blank canvas, Consumer Fintech and Personal RAG assistant, each card showing agent count, edge count, findings count and trifecta count.
Start with the system you are shippingOpen a worked example or import MCP, n8n, LangGraph, Bedrock, Foundry and other agent configs.
Question 4 of the Helmwart threat-model wizard, Did we do a good enough job, with an expense-reimbursement system loaded. A posture score of 47 out of 100, grade F, reads Incomplete: the threat model does not yet meet the minimum quality bar. Beside it, system scope captured 60 percent, threats enumerated 100 percent, mitigations assigned 0 percent, and three optional assurance passes not yet run. An audit summary lists 49 threats surfaced with 49 residual open.Question 4 of the Helmwart threat-model wizard, Did we do a good enough job, with an expense-reimbursement system loaded. A posture score of 47 out of 100, grade F, reads Incomplete: the threat model does not yet meet the minimum quality bar. Beside it, system scope captured 60 percent, threats enumerated 100 percent, mitigations assigned 0 percent, and three optional assurance passes not yet run. An audit summary lists 49 threats surfaced with 49 residual open.
See whether the model is good enoughThe wizard turns system scope, threats, mitigations and assurance checks into a clear ship-or-fix posture.
A Helmwart threat entry: T6, Intent Breaking and Goal Manipulation, marked critical, tagged MAESTRO L3 Agent Frameworks and Cross-Layer, cross-referenced to ATLAS techniques AML.T0051, AML.T0051.001, AML.T0054 and AML.T0065, with a definition and three worked injection examples.A Helmwart threat entry: T6, Intent Breaking and Goal Manipulation, marked critical, tagged MAESTRO L3 Agent Frameworks and Cross-Layer, cross-referenced to ATLAS techniques AML.T0051, AML.T0051.001, AML.T0054 and AML.T0065, with a definition and three worked injection examples.
Open a finding reviewers can understandThreat entries explain what is exposed, how the attack works, where the claim comes from, and which mitigation belongs with it.
The Helmwart compliance workspace with the Consumer Fintech sample assessed against NIST AI RMF 1.0. Control coverage reads 0 of 11 requirements, 119 gaps across 29 open findings. The four NIST sections Govern, Map, Measure and Manage each show their open counts, open findings by severity read 42 critical and 89 high, and the requirements list below is grouped by section.The Helmwart compliance workspace with the Consumer Fintech sample assessed against NIST AI RMF 1.0. Control coverage reads 0 of 11 requirements, 119 gaps across 29 open findings. The four NIST sections Govern, Map, Measure and Manage each show their open counts, open findings by severity read 42 critical and 89 high, and the requirements list below is grouped by section.
Hand over evidence when askedTranslate the threat model into controls and reports for security, governance and audit review.

Do the threat model before the review.

Start from a template or import a real config. Know the exposure, the fix, and the evidence before approval becomes a blocker.

Helmwart is a threat-modeling tool, not a safety certificate. It shows the risks your agent system creates, the controls that address them, and the evidence behind the decisions.