AgentGuard

Runtime Guard

Runtime Guard for AI Agent Actions

Evaluate documented shell, file, tool, network, secret, sensitive-write, and webhook-exfiltration action categories through the integration path available in your environment.

Coverage and enforcement depth depend on the selected integration.

Control surfaceReview ready
01Shell Commandsverify
02File Accessverify
03Tool Actionsverify
04Network Requestsverify
FEATURES / 01

Runtime Action Surface

AgentGuard publicly names seven high-risk action categories. Use them to define the actions your integration must observe.

Shell Commands

File Access

Tool Actions

Network Requests

Secret Access

Sensitive Writes

Webhook Exfiltration

Named categories describe the documented surface; they do not establish universal interception or blocking.

FEATURES / 02

Decide Before Execution

Observe a Documented Action

The selected hook, plugin, skill, command, or API path exposes an action for evaluation.

Request a Runtime Decision

The documented API surface includes tool-call, file, text, and runtime-decision endpoints.

Verify the Observed Outcome

Test the configured allow, block, or other returned behavior in a controlled workflow before production use.

Evidence

Public API documentation establishes endpoint groups, not latency, accuracy, or a universal enforcement outcome.

FEATURES / 03

Verify Integration Depth

First-party materials list different integration patterns across supported environments. Evaluate each workflow separately.

Group 1 title
Tool Hooks

Claude Code is documented with pre- and post-tool hooks. Hermes is documented with native tool hooks.

Group 2 title
Plugin Hooks and Patrol

OpenClaw is documented with plugin hooks, auto-scanning, and patrol capabilities.

Group 3 title
Skills and Commands

Codex CLI, Gemini CLI, Cursor, and GitHub Copilot are listed with skill- or command-based paths.

Group 4 title
MCP Hosts

MCP hosts are listed as an entry point, but third-party MCP runtime coverage remains limited and must be verified.

Next step

Review Integration Guidance

FEATURES / 04

Trace Data Flow

Column 1 titleLocal Mode
Column 1 copyPublic materials say full code, prompts, secrets, and file contents are not uploaded in local mode.
Column 2 titleCloud-Connected Use
Column 2 copyPublic materials say sanitized action previews, risk metadata, decisions, policy versions, and audit events may be sent.
BoundaryConfirm the current data path, policy source, cached-policy behavior, retention, and audit output for the selected integration.
FEATURES / 05

Scan Then Guard

Left titleBefore Trust: Deep Scan

Review skills, plugins, agents, and MCP servers for documented component risks.

Right titleDuring Execution: Runtime Guard

Evaluate named high-risk actions through the integration path available in the workflow.

Next step

Review Deep Scan

FEATURES / 06

Test Runtime Controls

Name the actions in scope.
Confirm the integration mode.
Define expected allow and high-risk outcomes.
Test online and offline behavior.
Inspect the evidence produced.
Document calls outside the control path.
Do all integrations provide the same protection depth?
No. The documented hook, plugin, skill, and command paths are different and must be tested separately.
What happens offline?
The Quickstart says offline use can rely on cached policy. Verify current behavior for the selected integration.
Are latency or accuracy metrics available?
No approved public metric is available in the reviewed evidence.

Verify a Runtime Path

Use the documented integration, verify expected outcomes, and record any action that remains outside the control path.