Skip to content
Stoa Labs

Services · 04 of 04

The surface where quality and security failures concentrate.

Agents are only as capable as the skills, tools, and connections around them, and that surface is where quality and security failures concentrate: published capabilities often weaken under measurement, and injection and tool-poisoning attacks target exactly the integrations teams add fastest.

Stoa Labs audits and hardens the capability surface of agent estates: what each extension can access, what authority it actually has, whether it measurably helps, and how it holds up against the attacks that matter.

Quality measured, not assumed Findings stay confidential Weeks, not quarters

01 · 1-2 weeks
The entry point

Capability Surface Audit

A fixed-scope diagnostic. We inventory the tools, skills, MCP servers, and subagents around your agents; evaluate skill quality against measured outcomes rather than plausibility; analyze permissions and authority paths; and assess exposure to prompt injection and tool poisoning.

It ends with a capability inventory, measured quality findings, a permission and authority analysis, prioritized security findings, and a remediation plan.

02 · Scoped by the audit

Hardening Engagement

Implementation of the audit's priorities: permission and policy-gate engineering, evaluated rework or retirement of weak skills, MCP server security remediation, injection-resistance measures, and monitoring signals for the capability surface.

Scope, timeline, and price are fixed in the proposal from the audit's findings.

The research behind it

This family is anchored by the lab's extensibility research: how agents acquire capabilities, and how those capabilities are evaluated, secured, and governed.

Agent Extensibility & Tooling, the research area

Start with the audit.

Tell us what your agents can reach, and when that surface was last reviewed.