Skip to content

Detection

AgentGuard looks for credentials, personal data and dangerous commands in every call's arguments, and for credentials in every result. What it finds drives policy conditions (sensitive_data), risk scores, session taint and redaction in audit logs and notifications.

Credentials

Three sources, combined:

Source Covers
gitleaks ruleset, vendored (MIT) 221 rules for provider tokens and keys: cloud, source hosting, payments, chat, AI APIs and a generic high-entropy key rule
AgentGuard patterns Private key blocks, JWTs, database connection strings, password=... pairs, short test-style GitHub and sk- tokens
Field names Values under keys like password, token, api_key, authorization

The gitleaks rules run on RE2 (the google-re2 package), the engine they were written for. Matching is linear time, so scanning attacker-controlled text such as a fetched web page cannot stall the agent (110 KB scans in about 20 ms). Keyword prefilters, entropy thresholds, allowlists and stopwords apply as they do in gitleaks; for example, AWS's documented example key is not flagged. Refresh the rules with:

python scripts/update_secret_rules.py      # latest gitleaks config, or --ref <commit>
python -m pytest -q                        # then review the diff

Categories reported: api_key, ssh_key, jwt, password, database_url.

Personal data

Category Detection Redacted in logs
credit_card 13–19 digits, known issuer prefix, Luhn checksum Yes
ssn US format with issuance rules (no 000, 666, 9xx areas) Yes
iban Country code and ISO 7064 mod 97 checksum Yes
email Address syntax No: often the action's subject
phone International +CC and North American formats No

Checksums keep false positives low: 4111 1111 1111 1112 and GB00 WEST ... are not reported. Outbound payloads with card numbers, SSNs or IBANs add 30 risk; other personal data adds 10. Policies can name any category:

- capability: email.send
  sensitive_data: [credit_card, ssn, iban]
  effect: deny

Commands

Shell commands are tokenized like a POSIX shell, split at ; & | && ||, newlines, $( ) and backticks, and unwrapped from bash -c, cmd /c, powershell -Command, eval, env, nohup, sudo, busybox and similar. Each simple command is judged by its program and flags.

Result Examples
Always denied Recursive forced deletion (rm -r -f, Remove-Item -Recurse -Force, find -delete), disk tools, world-writable or setuid permissions, disabling firewalls or security services, download-and-execute, decoded payloads piped into a shell, encoded PowerShell, credential files
Asks a human (risk 70) terraform destroy, kubectl delete, cloud CLI deletes, destructive SQL, git reset --hard, nc/socat in pipelines, command substitution in DNS lookups, inline interpreter code with network access or file deletion, secret-looking environment variables, environment dumps piped onward, run-time-built program names, generated code piped into an interpreter
Writes that ask Shell profiles, git hooks, CI workflows, systemd units, cron, launch agents, /etc, /var/log

Shell is too expressive for string analysis to be complete. Obfuscation is treated as a reason to ask rather than decoded. For untrusted workloads, use exact-command executors (ShellExecutor, ContainerExecutor), which run only argv lists you wrote. agentguard explain policy.yaml shell.execute --arg cmd="..." shows how any command is judged. See Benchmarks for measured recall and false-positive rates.

Changes to Git's core.hooksPath also raise risk to 70: redirecting hooks can run code on later Git operations or disable existing checks. This covers legacy assignments, --add, --replace-all, --unset, --unset-all, and modern config set/config unset, across config scopes and explicit files. Queries (config get, --get, or a key without a value) and unrelated settings such as user.name do not raise this concern. Ask-level concerns propagate through shell, cmd, PowerShell and eval wrappers, within the analyzer's nesting limit. This check does not cover every way of configuring hooks, such as Git aliases, direct config-file edits or command-scoped git -c overrides.