Roast Playbook: Fix in 30 Minutes
30 minutes, no drama. The fastest fixes after the roast — visible in your score.
"Not a Pentest" Notice: This guide is for hardening your own systems. No attack tools.
30-minute plan
1
Rotate secrets
Roll new API keys + tokens. Invalidate old ones immediately.
2
Egress allowlist
Allow only explicit destinations. Block exfiltration.
3
Enable mTLS
Encrypt and authenticate agent-to-agent traffic.
4
Enforce output schema
Validate outputs and block when they drift.
5
Enable audit logs
Log prompts + tool calls. Add SIEM hook.
Quick checklist
- ✅ Secrets & tokens rotated
- ✅ Egress allowlist active
- ✅ mTLS between agents
- ✅ Output schema enforced
- ✅ Audit logs to SIEM