Edge Copy setup link

AI Agent Governance Gap Analysis

Score your AI agent governance against Cakewalk's 25 checks, then get a scorecard and a 30/60/90 plan to close the gaps.

Signal

Signal describes package standing, not measured performance.

Scores your organisation's AI agent governance against 25 technical checks across 7 dimensions: agent inventory, credential mediation, policy enforcement, human-in-the-loop, least privilege, identity lifecycle and audit trail. Walks the checks with you and explains any of them on request, can run a read-only scan of your own agent setup (MCP servers, connectors, permission settings, plaintext credentials) to evidence checks instead of trusting self-report, and outputs a scored scorecard and a 30/60/90 remediation plan.

Example output

Terminal output
agent · agent-governance-gap-analysis
$ python3 scripts/scan.py --root .AGENT CONNECTIONS: 6 · highest blast radius: DatabaseCREDENTIALS IN PLAIN TEXT: 6   (values are never read out)line 3  postgresql connection-string password: 13 chars  [postgresql://admin:<redacted>@prod-db.internal:5432]cred1  fail  6 credential(s) in plain text in agent config. A compromised session yields replayable credentials.cred2  fail  Credentials sit in the agent runtime's own config, not managed separately.$ python3 scripts/scan.py --selftest✓ RESULT: PASS · no secret material in output
Input

Real run · python3 scripts/scan.py on the scanner's self-test fixture (.mcp.json with six fake credentials), 23 Sep 2026

Finding

Not met · cred1 and cred2: a database password sits in plain text in the agent's own MCP config

Exact evidence

line 3 · postgresql connection-string password, 13 chars · [postgresql://admin:<redacted>@prod-db.internal:5432] · 6 plaintext credentials found, 0 values printed

Uncertainty

One machine is one machine: a local scan can falsify an org-wide claim but never confirm one. Every finding is a proposal the user confirms or corrects.

Remediation

Move the credential behind a broker or gateway that injects auth server-side, rotate the password, then re-run the scan.

Before walking the 25 checks, the agent runs the skill's read-only scanner. It finds the Postgres password embedded in an MCP server's connection string, prints it only as <redacted>, and proposes cred1 and cred2 as not met from evidence. The right-hand output is a real run on the scanner's self-test fixture on 23 Sep 2026; the left-hand run without the skill is illustrative.