skulk
point-in-time · deterministic the report is the deliverable

AI security posture,
assessed honestly.

A point-in-time assessment of your RAG and agent stack — code, cloud, and your own stores. Every finding carries its evidence. Every report states what it did not assess.

56checks across the RAG and agent stack
4inputs: repo, cloud, declared intent, data plane
Cloud & self-hostedAWS, or infrastructure you run yourself
Read-onlynothing installed, nothing stays behind

Where a Skulk assessment fits — and when something else fits better

There are three established ways to secure an AI application, and they are not interchangeable. Skulk holds a fourth position: a point-in-time posture assessment with consultancy-depth findings and tool-grade consistency. Here is the honest comparison, including when to choose the others.

A security platform

Continuous AI-SPM across your cloud estate, correlated with wider cloud posture — and it discovers AI infrastructure well. Choose one when you run AI at scale and can staff a platform. It is a subscription and a deployment, and it discovers by cloud API.

A consultancy engagement

Human-led adversarial testing — prompt injection, jailbreaks, red teaming. Choose one when a critical system needs an attacker’s creativity. Scope, cost and findings vary with the team on the engagement.

A runtime guardrail

In-line defenses screening prompts and outputs in production. Choose one to protect a live perimeter. A guardrail enforces at runtime — it does not audit the entitlements and IAM paths behind it.

What a Skulk engagement gets you

Deterministic, so re-assessment means something

Same environment, same findings. The second report shows exactly what was fixed and what is new — no tester variance in between.

Evidence on every finding

A traced graph path, a file and line, or a named configuration field. If we cannot show it, we do not report it.

Checks your declared posture against your running system

Six checks compare what you told us to what we found — declared row-level security against the live catalog, declared agent identity against its actual execution role, declared providers and retired stores against the code that still calls them. Disagreement is the finding.

A declared-vs-observed record, dated

The report lays every declaration you made beside what we found — confirmed, contradicted, or not verifiable with the reason — and states how old your declaration is, so its confirmations are weighed against their freshness.

A ledger of what wasn’t assessed

Every report states its own limits. Nothing unparsed or unassessed is ever presented as clean.

Framework mapping built in

Every check carries OWASP LLM Top 10 and MITRE ATLAS mappings, with NIST AI RMF where defensible, so findings arrive in vocabulary your security team already reports in.

nothing stays behind no subscription no data leaves your side fixed, stated scope re-assessable

The honest boundary

A control-plane assessment has a hard edge. Pretending otherwise is how false comfort happens, so the edge is stated in every report.

Verified — static and control-plane

  • Entitlement and tenancy configuration, cloud and self-hosted
  • IAM and AI exfiltration paths
  • Agent permissions, approval gates, identity
  • Declared posture against the running system
  • Logging, retention and gateway posture

Referred out — and stated in the report

  • Runtime prompt-injection defense
  • Output filtering and DLP
  • Adversarial red-teaming
  • Anomaly detection
  • Whether a declared control is enforced at runtime

When these matter, the report says so — as recommendations, never as findings we didn’t verify.

One engagement. One report. Every claim traceable. Happy to walk through the architecture and controls against your own stack — no assessment required.
hello@skulksec.com