AgentRiskLayer

ARL Guardian · Public Preview

See what authority surfaces exist in an AI-agent repository.

Give Guardian a repository. It scans the source without running the agent and maps evidence for MCP, outbound network access, filesystem mutation, process execution, credential references and approval boundaries.

Runs locally. No source upload. No LLM. No API key. No Guardian account.

RC5

Install and run it locally.

Requirement: Node.js 22.5 or later.

Install:

npm install https://agentrisklayer.com/downloads/agentrisklayer-guardian-0.3.0-rc.5.tgz

Generate a customer-facing report:

npx --no-install arl-guardian report /path/to/your-agent

Generate the technical evidence appendix:

npx --no-install arl-guardian evidence /path/to/your-agent

SHA-256: eae7836e88e30902b13774f1e2b86d116d371d4c2ae3c30dd4fba71b7cf0ca35

What it gives you

A capability map with evidence, not a fake security score.

Guardian reduces a repository into a review surface so developers and assessors can see where potentially important authority lives.

01

Capability discovery

MCP, network, process execution, filesystem writes, credentials and approval controls.

02

Context separation

Separates agent-linked evidence from backend code, examples, tests, documentation and tooling.

03

Exact evidence

Keeps file and line references so a human can verify the source directly.

04

ARL handoff

Produces review questions and conservative candidate facts for human confirmation.

Real-world validation

Tested against a real public agent repository.

Browser Use · RC3 validation

434 files

Scanned without truncation.

435 evidence refs

Across six capability families.

MCP

110 refs, 13 agent-linked for human review.

Process execution

24 refs, 0 agent-linked after removing a false positive.

The boundary

Guardian discovers. AgentRiskLayer assesses.

Guardianobservational capability discovery

Evidenceexact source references

ARLhuman-led security assessment

Humanfinal accountable decision

Need the result reviewed?

Turn Guardian evidence into an ARL assessment.

Guardian observations are not findings, severity decisions or deployment verdicts. AgentRiskLayer reviews applicability, validates evidence, performs authorised testing where required, and retests affected controls.

Request an Assessment