An example, not your data: this is what uvx ranwhat demo --html report.html writes for a bundled sample agent. What the scores mean · Run it on your own
An underwriter cannot distinguish this deployment from the worst case, because it cannot produce the tool call, the authority used, and the guardrail decision for a named past action. Expect declined coverage or flat-rate penalty pricing regardless of how well the agent actually behaves.
5 permission(s) that can move money or destroy data have not been exercised in the observed window. This is pure downside: full liability, zero utility.
Traces do not carry tool name, arguments, credential identity and guardrail decision. You cannot answer the question an underwriter or a plaintiff will ask: what exactly did the agent do, and under whose authority.
These permissions allow irreversible destruction of data or infrastructure. Several also allow deletion of the records that would evidence the action.
The agent can move money with no per-action spend cap configured.
Documented human oversight is becoming a condition of coverage, not a best practice. Its absence shifts liability squarely onto the operator who configured the agent.
There is no documented mechanism to halt the agent mid-task.
1 scope(s) are not in the capability catalog and were classified by action verb. Confirm these manually.
Usage for these providers was declared in the profile rather than pulled from the provider's own audit trail. The findings hold only as far as that declaration does. Run `uvx ranwhat scan <profile> --pull-usage` to make them independently evidenced.
| Scope | Provider | Authority | Reversible | Usage |
|---|---|---|---|---|
s3:*Full S3 control | aws | destructive | no | unused |
workflowUpdate GitHub Actions workflows | github | destructive | no | unused |
https://www.googleapis.com/auth/driveFull Drive access | destructive | no | unused | |
charges:writeCreate and capture charges | stripe | financial | no | unused |
refunds:writeIssue refunds | stripe | financial | no | used |
transfers:writeMove money to connected accounts | stripe | financial | no | unused |
ses:SendEmailSend email | aws | write | no | unused |
lambda:InvokeFunctionInvoke functions | aws | write | yes | used |
dynamodb:PutItemdynamodb:PutItem | aws | write | no | unused |
repoFull control of private repositories | github | write | no | unused |
gistCreate gists | github | write | no | unused |
https://www.googleapis.com/auth/gmail.modifyRead, send, modify and label mail | write | no | used | |
https://www.googleapis.com/auth/gmail.sendSend mail as the user | write | no | used | |
https://www.googleapis.com/auth/calendarRead/write calendar | write | yes | unused | |
https://www.googleapis.com/auth/contactsRead/write contacts | write | yes | unused | |
chat:writePost messages | slack | write | no | used |
customers:writeModify customer records | stripe | write | yes | unused |
read:orgRead org membership | github | read | yes | used |
channels:historyRead public channel history | slack | read | yes | used |
groups:historyRead private channel history | slack | read | yes | unused |
im:historyRead direct messages | slack | read | yes | unused |
files:readRead files | slack | read | yes | unused |
customers:readRead customer records | stripe | read | yes | used |