01
- Tool Call Validation
- Intercept and validate every tool call before execution. Block dangerous operations like file deletion, shell commands, and unauthorized API calls.
02
- Privilege Escalation Detection
- Detect and block attempts to escalate privileges, such as agents trying to modify permissions or access restricted resources.
03
- Behavior Monitoring
- Track agent behavior over time to establish baselines and detect anomalies like unusual tool usage patterns or rapid-fire operations.
04
- Human-in-the-Loop
- Require human approval for sensitive operations like sending emails, modifying user data, or executing financial transactions.
05
- Session Isolation
- Isolate agent sessions to prevent cross-contamination and limit the blast radius of compromised agents.
06
- Real-time Alerts
- Get instant notifications when suspicious agent behavior is detected. Integrate with Slack, PagerDuty, and webhooks.
07
- Tool Injection Detection
- Detect and block attempts to inject malicious tool calls or manipulate agent tool usage through crafted prompts targeting function-calling workflows.
08
- Jailbreak Detection (LLM)
- LLM-powered jailbreak detection catches sophisticated bypass attempts that evade traditional pattern matching, including multi-turn, encoded, and role-play attacks.
09
- OpenClaw Agent Defense
- Purpose-built protection for OpenClaw agents: defend against indirect prompt injection and tool-hijacking exploits, and validate skill marketplace packages.
10
- Multi-Turn Intent Drift Detection
- Detect crescendo attacks and slow-burn manipulation across multi-turn conversations. Identifies gradual intent drift before agents are compromised.
11
- Agent Identity Registry
- Register agents and issue a per-agent credential (pgag_, bcrypt-hashed at rest, shown once), rotatable and revocable through the API. Requests today carry a self-asserted agent ID; credential checking on the request path is on the roadmap, not yet enabled.
12
- Behavioral Drift Detection
- Establish behavioral baselines using tool-usage distributions and detect drift via Jensen-Shannon divergence. Alerts fire when an agent's behavior shifts beyond the configured threshold.
13
- Tamper-Evident Audit Trail
- Every audit event is SHA-256 hash-chained to its predecessor, forming a cryptographic append-only chain. Verify chain integrity over any time range with a single API call.
14
- Content Safety Classification
- Classify harmful intent using an LLM safety classifier. Detect violent, sexual, self-harm, and hateful content before it reaches your agents or users.
15
- EU AI Act & ISO 42001 Aligned
- Technical controls mapped to EU AI Act Articles 9-15 and ISO/IEC 42001 Annex A. Risk management, automated record-keeping, transparency, human oversight, and governance reporting, built in, not bolted on.
16
- Framework Integrations
- Native support for LangChain, LangGraph, CrewAI, OpenClaw, Pydantic AI, OpenAI Agents SDK, and Vercel AI SDK. Drop-in security for any agent framework.