AgentGuard

AI Agent Security for Security Teams

Review documented component checks, pre-execution action evaluation, data handling, and first-party advisories before deciding how AgentGuard fits your security program.

The reviewed evidence does not establish a complete security-operations platform.

Separate Failure Modes

Untrusted Components

Skills, plugins, agents, and MCP servers can introduce documented component risks.

Evaluate Deep Scan
High-Impact Runtime Actions

Shell, file, tool, network, secret, sensitive-write, and webhook actions require an observable decision point.

Evaluate Runtime Guard
MCP Coverage Gaps

Third-party MCP server runtime calls may remain outside complete monitoring or blocking coverage.

Evaluate the host and integration path
Unclear Data Handling

Local and cloud-connected paths expose different privacy, metadata, and audit questions.

Verify the data path

Map Risk to Controls

Row 1Component provenance and malicious contentDeep ScanNamed component and risk categoriesVerify scan depth and output
Row 2High-risk actions before executionRuntime GuardNamed action categories and runtime API groupsVerify integration depth and outcome
Row 3OpenClaw workspace driftOpenClaw PatrolFour documented change typesVerify schedule and response path
Row 4Threat research contextAgent Security AdvisorPublic first-party advisoriesVerify update and reuse policy
Row 5Policy and audit operationsAPI groupsEndpoint groups are listedVerify the actual workflow

An API group or public page is evidence of a technical surface, not proof of a complete operational workflow.

Verify What the Integration Can See and What the Data Path Sends

Integration paths

Hooks, plugins, skills, commands, APIs, and MCP hosts represent different control paths. Confirm whether the chosen path can observe the actions in scope.

01HooksPlugins
02SkillsCommands
03APIsMCP hosts
Local

Public materials say local mode does not upload full code, prompts, secrets, or file contents.

Cloud-connected

Cloud-connected use may send sanitized action previews, risk metadata, decisions, policy versions, and audit events.

  • Observation depth
  • Data sent
  • Policy source
  • Offline behavior
  • Retention
  • Access

Design the Evaluation

Homepage — documented product scope and qualified FAQ statements

Quickstart — installation and integration modes

API Reference — documented endpoint groups

GitHub Repository — package, CLI, and source evidence

Agent Security Advisor — public first-party threat examples

Keep Gaps Visible

The reviewed public evidence does not establish a complete implementation for the following requirements.

Role-based access
Approval workflows
Reporting
Retention
Audit export
Certifications
Security-operations integration
Support commitments

Run a Bounded Evaluation

List the agents, components, tools, actions, and data in scope.
Map each risk to a documented control.
Define expected allow and high-risk outcomes.
Specify required evidence and access.
Record unsupported workflows.
Assign owners for residual gaps.
Is a complete RBAC or approval workflow publicly documented?
No. The reviewed public evidence does not establish a complete workflow.
Are policy and audit API groups documented?
Yes, but live behavior and the surrounding operational workflow were not verified in this audit.
Which certifications are available?
No certification claim is approved in the current product fact base.

Evaluate in Your Environment

Define the users, decisions, evidence, and ownership required before choosing the implementation path.