This page summarizes current first-party public evidence, identifies conflicts and unknowns, and converts the evidence into buyer verification tasks.
Resources / Reviews / AgentGuard
AgentGuard Review: Documented Features and Current Limits
Review AgentGuard's public product surfaces, setup evidence, integration modes, data boundaries, fit, limitations, and the questions that remain unresolved.
Disclosure and Review Method
Public homepage
Quickstart
API Reference
GitHub repository and README
No live API behavior, performance, bypass resistance, false-positive rate, or production-scale operation is established by this review.
Current pricing, plan allocation, complete integration depth, enterprise commitments, and final Legal-approved privacy wording.
AgentGuard Product Snapshot
AI Agent Security for AI Developers; the public repository describes an open-source runtime security layer for AI coding agents.
Primary public surfaces
Runtime Guard, Deep Scan, and OpenClaw Environment Patrol.
Developer entry points
Docs, Quickstart, API Reference, CLI, and public GitHub repository.
Runtime analysis and decision endpoints; repository, package, MCP server, and URL scan endpoints.
License
MIT in the public repository and package metadata.
Review status
Evidence profile only; no independent safety verdict.
Runtime Guard
AgentGuard publicly describes Runtime Guard as evaluating named high-risk actions before execution.
Shell commands
File access
Tool actions
Network requests
Secret access
Sensitive writes
Webhook exfiltration
Which host integration places the decision before execution?
Which actions are observable in that mode?
What evidence is returned?
Which paths remain outside the integration?
Review Runtime Guard
/features/runtime-guard
Deep Scan
Skills
Plugins
MCP servers
Agents
Prompt injection
Malicious tools
Credential leaks
Backdoors
Which inputs and package types are accepted?
What evidence accompanies a finding?
How are updates re-scanned?
The public evidence supports named component targets and risk categories, not universal detection or a guarantee of safety.
Review Deep Scan
/features/deep-scan
OpenClaw Environment Patrol
Suspicious skills
Modified plugins
New MCP servers
The Quickstart describes plugin hooks, auto-scanning, and daily patrol for OpenClaw.
This evidence is specific to the documented OpenClaw workflow and must not be generalized to every agent or host.
Review OpenClaw Patrol
/features/openclaw-patrol
Setup and Integration Evidence
Claude Code
Pre- and post-tool hooks
Exact action coverage and enforcement behavior in the current version
OpenClaw
Plugin hooks, auto-scanning, and daily patrol
Workspace scope, schedule, and response behavior
Hermes
Native tool hooks
Current supported actions and configuration
Codex CLI, Gemini CLI, Cursor, GitHub Copilot
Whether the path provides guidance, scanning, or enforceable runtime coverage
MCP hosts
Host-specific runtime visibility and the documented third-party MCP limitation
CLI and API
Authentication, current schema, errors, limits, and live production behavior
Open the Quickstart
/docs
Data Handling
AgentGuard public materials say local mode does not upload full code, prompts, secrets, or file contents.
Public materials say connected use may send sanitized action previews, risk metadata, decisions, policy versions, and audit events. The Quickstart also describes redacted metadata and audit events when needed.
The final authoritative privacy policy, retention, regional processing, subprocessors, and enterprise contractual terms are not established by this evidence profile.
Review AgentGuard Security
/security
Fit, Limitations, and Unknowns
Developers and security teams evaluating coding-agent actions, components, OpenClaw workspaces, and selected integration paths.
AgentGuard's public FAQ says it cannot fully monitor or block all third-party MCP server runtime calls.
Public materials conflict on whether the product has 20 or 24 security rules. This review does not publish an exact count.
Current pricing, plans, usage limits, enterprise support, and contractual commitments.
Complete host-by-host depth, complete deployment model, and complete governance lifecycle.
AgentGuard Verification Checklist
Evidence Summary
AgentGuard has public evidence for named runtime action checks, component scanning, OpenClaw workspace checks, developer entry points, and qualified local and cloud-connected data statements. It is reasonable to evaluate when those documented surfaces match the target workflow.
This review does not establish independent safety, complete third-party MCP runtime coverage, identical protection across every host, current commercial terms, or a complete AI CISO lifecycle.
Frequently Asked Questions
Is this an independent AgentGuard review?
What does AgentGuard publicly include?
Is AgentGuard open source?
What data may cloud-connected use send?
What are AgentGuard's current material limitations?
Verify the Evaluation in Your Own Workflow
Use equal test conditions, current first-party evidence, and explicit acceptance criteria before making a decision.