Shell Commands
Runtime Guard
Runtime Guard for AI Agent Actions
Evaluate documented shell, file, tool, network, secret, sensitive-write, and webhook-exfiltration action categories through the integration path available in your environment.
Coverage and enforcement depth depend on the selected integration.
Runtime Action Surface
AgentGuard publicly names seven high-risk action categories. Use them to define the actions your integration must observe.
File Access
Tool Actions
Network Requests
Secret Access
Sensitive Writes
Named categories describe the documented surface; they do not establish universal interception or blocking.
Decide Before Execution
The selected hook, plugin, skill, command, or API path exposes an action for evaluation.
The documented API surface includes tool-call, file, text, and runtime-decision endpoints.
Test the configured allow, block, or other returned behavior in a controlled workflow before production use.
Public API documentation establishes endpoint groups, not latency, accuracy, or a universal enforcement outcome.
Verify Integration Depth
First-party materials list different integration patterns across supported environments. Evaluate each workflow separately.
Claude Code is documented with pre- and post-tool hooks. Hermes is documented with native tool hooks.
OpenClaw is documented with plugin hooks, auto-scanning, and patrol capabilities.
Codex CLI, Gemini CLI, Cursor, and GitHub Copilot are listed with skill- or command-based paths.
MCP hosts are listed as an entry point, but third-party MCP runtime coverage remains limited and must be verified.
Review Integration Guidance
Trace Data Flow
Scan Then Guard
Review skills, plugins, agents, and MCP servers for documented component risks.
Evaluate named high-risk actions through the integration path available in the workflow.
Review Deep Scan
Test Runtime Controls
Do all integrations provide the same protection depth?
What happens offline?
Are latency or accuracy metrics available?
Verify a Runtime Path
Use the documented integration, verify expected outcomes, and record any action that remains outside the control path.