AgentGuard

Resources / Reviews / AgentGuard

AgentGuard Review: Documented Features and Current Limits

Review AgentGuard's public product surfaces, setup evidence, integration modes, data boundaries, fit, limitations, and the questions that remain unresolved.

Evaluation frameReview ready
01This page summarizes current first-party public evidence, identifies conflicts and unknowns, and converts the evidence into buyer verification tasks.verify
02Public homepageverify
03Quickstartverify
04API Referenceverify
EVALUATION / 01

Disclosure and Review Method

Method

This page summarizes current first-party public evidence, identifies conflicts and unknowns, and converts the evidence into buyer verification tasks.

Sources Reviewed

Public homepage

Sources Reviewed

Quickstart

Sources Reviewed

API Reference

Sources Reviewed

GitHub repository and README

Sources Reviewed
Package metadata

No live API behavior, performance, bypass resistance, false-positive rate, or production-scale operation is established by this review.

Unknown

Current pricing, plan allocation, complete integration depth, enterprise commitments, and final Legal-approved privacy wording.

EVALUATION / 02

AgentGuard Product Snapshot

Public positioning

AI Agent Security for AI Developers; the public repository describes an open-source runtime security layer for AI coding agents.

Primary public surfaces

Runtime Guard, Deep Scan, and OpenClaw Environment Patrol.

Developer entry points

Docs, Quickstart, API Reference, CLI, and public GitHub repository.

API groups

Runtime analysis and decision endpoints; repository, package, MCP server, and URL scan endpoints.

License

MIT in the public repository and package metadata.

Review status

Evidence profile only; no independent safety verdict.

EVALUATION / 03

Runtime Guard

Documented Surface

AgentGuard publicly describes Runtime Guard as evaluating named high-risk actions before execution.

Named Action Categories

Shell commands

Named Action Categories

File access

Named Action Categories

Tool actions

Named Action Categories

Network requests

Named Action Categories

Secret access

Named Action Categories

Sensitive writes

Named Action Categories

Webhook exfiltration

Buyer Questions

Which host integration places the decision before execution?

Buyer Questions

Which actions are observable in that mode?

Buyer Questions

What evidence is returned?

Buyer Questions

Which paths remain outside the integration?

Next step

Review Runtime Guard

Next step

/features/runtime-guard

EVALUATION / 04

Deep Scan

Components

Skills

Components

Plugins

Components

MCP servers

Components

Agents

Named Risk Categories

Prompt injection

Named Risk Categories

Malicious tools

Named Risk Categories

Credential leaks

Named Risk Categories

Backdoors

Buyer Questions

Which inputs and package types are accepted?

Buyer Questions

What evidence accompanies a finding?

Buyer Questions

How are updates re-scanned?

Buyer Questions
Which risks are outside the named checks?

The public evidence supports named component targets and risk categories, not universal detection or a guarantee of safety.

Next step

Review Deep Scan

Next step

/features/deep-scan

EVALUATION / 05

OpenClaw Environment Patrol

Documented Checks

Suspicious skills

Documented Checks

Modified plugins

Documented Checks

New MCP servers

Documented Checks
Drift in trusted files

The Quickstart describes plugin hooks, auto-scanning, and daily patrol for OpenClaw.

Boundary

This evidence is specific to the documented OpenClaw workflow and must not be generalized to every agent or host.

Next step

Review OpenClaw Patrol

Next step

/features/openclaw-patrol

EVALUATION / 06

Setup and Integration Evidence

Claude Code

Pre- and post-tool hooks

Exact action coverage and enforcement behavior in the current version

OpenClaw

Plugin hooks, auto-scanning, and daily patrol

Workspace scope, schedule, and response behavior

Hermes

Native tool hooks

Current supported actions and configuration

Codex CLI, Gemini CLI, Cursor, GitHub Copilot

Skill or command paths are described

Whether the path provides guidance, scanning, or enforceable runtime coverage

MCP hosts

MCP-related entry points are described

Host-specific runtime visibility and the documented third-party MCP limitation

CLI and API

CLI commands and runtime/scan endpoint groups are public

Authentication, current schema, errors, limits, and live production behavior

Setup CTA

Open the Quickstart

Setup CTA

/docs

EVALUATION / 07

Data Handling

Local Mode

AgentGuard public materials say local mode does not upload full code, prompts, secrets, or file contents.

Cloud-Connected Use

Public materials say connected use may send sanitized action previews, risk metadata, decisions, policy versions, and audit events. The Quickstart also describes redacted metadata and audit events when needed.

Offline Behavior
The Quickstart says cached policy can be used offline.

The final authoritative privacy policy, retention, regional processing, subprocessors, and enterprise contractual terms are not established by this evidence profile.

Next step

Review AgentGuard Security

Next step

/security

EVALUATION / 08

Fit, Limitations, and Unknowns

Clearest Evidence-Backed Fit

Developers and security teams evaluating coding-agent actions, components, OpenClaw workspaces, and selected integration paths.

Material Limit

AgentGuard's public FAQ says it cannot fully monitor or block all third-party MCP server runtime calls.

Integration Limit
Protection depth varies across hook, plugin, skill, and command modes.

Public materials conflict on whether the product has 20 or 24 security rules. This review does not publish an exact count.

Commercial Unknowns

Current pricing, plans, usage limits, enterprise support, and contractual commitments.

Product Unknowns

Complete host-by-host depth, complete deployment model, and complete governance lifecycle.

EVALUATION / 09

AgentGuard Verification Checklist

Select the exact host, integration mode, workflow, and users in scope.
Confirm which actions are evaluated before execution in that mode.
Scan representative components and inspect the evidence returned.
Test known-safe and high-risk paths with expected outcomes recorded in advance.
Trace local, connected, redacted, and retained data for the test.
Review the third-party MCP runtime gap in the target architecture.
Resolve pricing, plan, usage, support, and enterprise unknowns.
Record residual paths, exceptions, operating owners, and the next review trigger.
Contact AgentGuard with the Test Scope
/contact
EVALUATION / 10

Evidence Summary

Summary

AgentGuard has public evidence for named runtime action checks, component scanning, OpenClaw workspace checks, developer entry points, and qualified local and cloud-connected data statements. It is reasonable to evaluate when those documented surfaces match the target workflow.

Not Established

This review does not establish independent safety, complete third-party MCP runtime coverage, identical protection across every host, current commercial terms, or a complete AI CISO lifecycle.

EVALUATION / 11

Frequently Asked Questions

Is this an independent AgentGuard review?
No. AgentGuard publishes this vendor-authored evidence profile of its own product.
What does AgentGuard publicly include?
The public surface includes Runtime Guard, Deep Scan, OpenClaw Environment Patrol, Docs, API groups, a public repository, and advisories.
Is AgentGuard open source?
The public repository and package metadata identify the available project under the MIT license. Review the current repository before relying on a specific release or package state.
What data may cloud-connected use send?
Public materials describe sanitized or redacted action and risk metadata, decisions, policy versions, and audit events.
What are AgentGuard's current material limitations?
Third-party MCP runtime coverage is incomplete, integration depth varies, the public rule count conflicts, and current commercial and enterprise terms remain unresolved.

Verify the Evaluation in Your Own Workflow

Use equal test conditions, current first-party evidence, and explicit acceptance criteria before making a decision.