Detect and Remediate Risks
As AI agents are deployed at scale, security threats such as prompt injection, jailbreak attacks, obfuscation smuggling, and privacy leaks are becoming increasingly prominent. Agent Security Center provides various detection and protection methods, including baseline detection and vulnerability scanning, to help you quickly identify and intercept agent security risks.
Before you begin
Connected your AI assets to Agent Security Center.
Detection method comparison
Different detection methods are suitable for different scenarios. Choose based on your needs:
Criteria | Scheduled automatic detection | Manual detection |
Scenario | Daily security inspection and continuous monitoring of asset risk status. | Immediate verification of risk status after configuration changes. |
Detection mode | Automatic | Manual |
Trigger | Runs automatically once per day. | Manually triggered. |
Result storage | Synchronized to the Agent Threat list. | Synchronized to the Agent Threat list. |
Cost | Free during the public beta phase. | Free during the public beta phase. |
Detect Agent risks
Detection notes
Duration: Varies based on asset complexity.
System impact: Detection is read-only and does not affect running workloads.
Result validity: Results reflect the risk status at scan time. Re-detect after configuration changes.
System scheduled automatic detection
After you connect AI assets to Agent Security, the system scans all connected assets once daily.
Scan frequency: Once per day, automatically.
Scan scope: All connected AI assets.
Results: Viewable and actionable in the risk event list under Agent Threat.
Manual detection
To perform manual detection:
Access the Security Center console - Agent Security Center - Agent Overview. At the top of the left side of the page, select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.
In the Connected Platforms section, click Asset synchronization in the upper-right corner.
The system synchronizes assets from the platform, including AI Agent, Model Service, toolset, Dataset, and Application Configurations, and performs a risk assessment.
NoteAsset synchronization may take some time.
Enable real-time protection
Agent Security Center provides real-time defense capabilities to protect Agents on the AI platform during runtime, ensuring their stable operation. For detailed steps, see Install the defense plugin.
View and handle risk events
Access the Security Center console - Agent Security Center - Agent Risks. At the top of the left side of the page, select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.
On the Risk Events page, in the Actions column for the target event, click Handle.
On the risk event details page, review the details. After assessing the risk, choose one of the following handling methods:
Manual handling: Follow the Recommended Solution or Suggestions on the details page to fix the issue in the Agent application's code or configuration.
Ignore: If the current risk is acceptable, click Ignore. The risk event will no longer appear in the pending list. If the same risk is detected in the next scan, a new risk event is generated.
Rescan: To verify the result of manual handling or re-detect the current AI asset, click Rescan.
ImportantThis applies only to risks originating from Agent Security. Detection takes time; you can view progress in the console.
A rescan runs a full detection on the AI asset associated with the current risk event, verifying whether the current risk is resolved and checking for additional risks.
Billing
During the public beta phase, scheduled automatic detection and manual detection are free.
Starting August 25, 2026, the defense plugin provided by Agent Security Center will begin commercial billing. For more information, see Agent Security Center defense capabilities official commercial billing announcement.