Agents are the first software that can be talked into misbehaving. Read that twice. Everything in an audit flows from it. - Prompt injection: can a webpage, document, or message the agent reads override its instructions? - Tool permissions: does the agent have write access it does not need? Overprivileged tools turn a confused agent into a destructive one. - Secrets handling: are API keys passing through prompts where they leak into logs? - Data egress: which models see your data, which third parties touch it? - Model supply chain: open weights keep data local but put security on you; APIs push inference elsewhere. Neither is automatically safer. Assume the agent will be tricked. Eventually it will be. Plan for that day now. Want the agent without the homework? PrivateLLM deploy sets up your private LLM on AWS for $50 plus usage.