Free tool · Audit
What can the things you installed actually reach?
Not a scanner — a scanner would have to reach your systems, and this site reaches nothing. Six questions about what you installed at speed, ranked by what it could actually cost you.
The short answer
The question is not whether a tool is trustworthy but what it can reach if it is not. Rank by blast radius: an integration holding a write-scoped token to your email or finance system is a different order of problem from a read-only calendar connection. Inventory what is installed, what each holds, and remove what has not earned its access — which is usually most of it.
Almost every team that adopted AI quickly has an inventory problem rather than a security problem. Things were installed to try, they worked, and nobody removed them or wrote down what they could touch.
These six questions rank exposure by blast radius rather than by how frightening a category sounds. A read-only integration nobody uses is clutter; a write-scoped one nobody remembers installing is the actual risk.
Six questions about what is installed
Answer for your whole team, not your own laptop. The gap between those two is usually the finding.
—
Why it does not scan
Because a scanner has to reach your systems, and nothing on this site reaches anything. The scanner version lives in Agent Market Store, which is in private beta. The categories are the same ones it checks.
The cheapest fix, and it is free
Open the OAuth or connected-apps page of your email, storage and finance systems today and read the list aloud. Most teams find at least one thing they cannot account for, and revoking it costs nothing. Do that before buying any audit, including ours.
Questions people actually ask
How do I audit AI tools and extensions my team has installed?
Start with the connected-apps or OAuth page of your email, storage and finance systems — it is free and takes about twenty minutes. List what is there, what scope each holds, and who granted it. Rank by blast radius: anything with write access to money or mail first, then anything nobody can account for.
What is the biggest risk from AI agent integrations?
An integration holding write access to a system that moves money or sends mail as you. That single category is what turns a mistake or a compromise into an incident. Read-only connections to low-value systems are clutter rather than danger, and treating both as equally urgent is why the urgent one does not get fixed.
Are browser extensions a real risk for business systems?
Yes, and they are the least reviewed category. An extension permitted to read and change data on all websites can see every internal system a logged-in browser can reach. Audit them per profile and keep work profiles separate from personal ones.
Why is this not an automatic scan?
Because a scanner has to reach your systems, and no tool on this site reaches anything. The scanner lives in Agent Market Store, which is in private beta. The categories checked here are the same ones it uses.
Sources
- The six categories and the blast-radius ordering are Noxia’s own, drawn from building Agent Market Store. They are not a standard, a framework or a certification. — our opinion, labelled
- Nothing is scanned, no system is named, and no answer leaves the page. The page counts its own views, anonymously and first-party, and nothing you answer is part of that count. — verifiable in your browser’s network tab
Checked 8 September 2026. Numbers that move — leaderboards, live indices — are re-checked every 30 days; annual datasets and rules in force every six months; dated research once a year. If something here has gone stale before we got to it, tell us and we will correct it and say what changed.
The list is free. The removal is the work.
If the top item fired, revoke it today without waiting for us. If the list is long and nobody owns it, that is a fixed-fee audit and the fix is quoted separately — bundling them makes the list longer.
Start the conversation