Architecture-specific review
LangChain agent security review
A LangChain or LangGraph agent is a workflow with tools, state and external data, not just a model call. Review the paths the agent can take, the permissions its tools carry, what survives between runs, and which actions a person must approve.
Start an AI security review →Review scope
What the reviewer needs to establish
Scope the deployed graph and its application services: model provider, tools, retrieval sources, checkpoint store and downstream systems. A framework's interrupt or checkpointer is a building block; the team's authorization, storage and approval design still needs evidence.
Entry points and trust boundaries
Which user, document, tool result or webhook can enter the graph? Where can untrusted content influence a later model or tool step?
Evidence to request: Graph definition, input and retrieval data-flow diagram, source labels, and adversarial tests that cross each lower-trust boundary.
Tool execution authority
Which tools can read, write or send data? Does each handler check the originating user's permission and constrain its own service credential?
Evidence to request: Tool registry and schemas, handler authorization code, credential scopes, negative permission tests, and audit events for side effects.
State and checkpoint access
What conversation or graph state is persisted, how is it keyed to a user or tenant, and who can resume or inspect a prior run?
Evidence to request: Checkpointer configuration, thread identifier design, storage access policy, retention policy, and cross-tenant read/resume tests.
Approval and resumption
Which consequential steps pause for a person? Can a resumed run bypass approval or use stale permissions after the pause?
Evidence to request: Interrupt locations, approval UI and role checks, resume-path tests, expired-permission tests, and a record of who approved each action.
Failure paths and decision
What happens after a failed tool call, retry or partially completed action? Which gaps remain before the agent can reach production?
Evidence to request: Retry and idempotency design, rollback or compensation tests, open controls with owners, and the signed review decision.
Architecture example
Follow authority and data end to end
A model endpoint is one component. The security decision also depends on the identity that calls it, the data it receives, the actions it can trigger, and who accepts the remaining risk.
For an agent that drafts and sends customer replies: customer message → retrieved account context → draft response → approval interrupt → send-email tool. Check that the retrieved account belongs to the requester, the approval applies to the exact draft, and the send tool rechecks authority when the run resumes.
From review to decision
Describe the system, confirm its architecture, examine threats and required controls, attach evidence, and record a human clearance decision. Unknown or missing evidence remains visible; it is not treated as a passed control.
Read the review methodology →