# Turn AI risk into a review you can act on.

> Inspect prompts, MCP manifests, agent architectures and vendor answers with focused security tools and explicit review boundaries.

Canonical page: https://prompterjack.com/products/security-review

## Choose the right review

Use the Injection Test Lab for prompt attack tests, Guardrail Forge for proposed protections, the MCP Tool Scanner for manifest risks, and Architecture Risk Review for system-level concerns. Vendor Assessment helps structure a separate supplier review.

## Keep findings explainable

Read the rule, evidence and suggested mitigation. Framework mappings such as OWASP and MITRE ATLAS provide context for a finding; a mapping does not demonstrate compliance or comprehensive coverage.

## Test the change

After changing a prompt, tool permission or architecture, rerun the relevant check and test representative legitimate inputs. A mitigation that blocks useful work may need adjustment.

## Know the boundary

Static checks and deterministic rubrics have false positives and false negatives. A passing result does not establish the absence of vulnerabilities, prompt injection or data leakage. Keep production review and specialist assessment proportional to the risk.

## Is this a security certification?

No. These tools support an engineering review. They do not provide a penetration-test attestation, certification or a guarantee that your application is secure.

## Next step

[Explore security tools](https://prompterjack.com/security)
