Skip to the card

Card 727 of 9902026-10-06 issue

Observed arrival · 2026-10-06

Scopehaven tests what AI agents can actually access

scopehaven.dev Visit website
Editorial interest 80/100 Selection signal · not a rating of the site

A permission-testing service for AI apps and agents that checks data access and tool actions, records evidence, and reruns checks after fixes.

Landing page captured for the 2026-10-06 issue.
For
Teams testing permissions in AI apps and agents
Worth noticing
Its demo suite maps checks to OWASP and CWE identifiers, while stating those mappings do not imply equivalence or coverage.

Field notes

Teams write down the user, data or tool, and action that should be allowed or blocked; Scopehaven says it runs both positive and negative checks, saves evidence, then reruns the same checks on a patched build. The homepage’s pilot figure—two failures in 14 cases—comes from an internal pilot with synthetic data. Its demo suite maps checks to OWASP and CWE identifiers, while explicitly disclaiming equivalence or coverage.

Observed signals

Read the marks

Editorial observations of this landing page, not a rating.

○OpenPublic substance visible
⊠LoginAccess appeared gated
✦PrettyNotable craft visible
●ProPolished or operationally mature
◎NicheUnusually specific use

One card from the complete issue

Original Bugs Included

353,261 arrived 1,000 judged 990 catalogued Enter the complete issue
scopehaven.dev

Landing page observed 2026-10-06. The live site may have changed.