Untrusted content
Instruction-like text in the material an agent reads.
The ClawMetry detector library
See what can go unnoticed in an agent workflow, what ClawMetry detects, and what to check next.
For people running agents such as Claude Code, Codex and OpenClaw. Coverage depends on the telemetry and configuration available to ClawMetry.
File changes, credentials, destinations and privilege requests.
File blast radius
See when an agent task reaches more files than expected.
Explore the detector →Credential access
Catch a sensitive file read inside an ordinary task.
Explore the detector →Network egress
Notice unfamiliar destinations in captured agent commands.
Explore the detector →Privilege change
Catch recorded commands that request elevated access.
Explore the detector →Instruction-like text in the material an agent reads.
Executable configuration and changes to the components an agent loads.
Repository config execution
Find executable configuration that a normal tool call can hide.
Explore the detector →Agent config tamper
Notice hooks and changes to the files that guide an agent.
Explore the detector →Package install scripts
See executable lifecycle hooks before overlooking them in a manifest.
Explore the detector →Agent component change
Track added or changed MCP servers, skills and plugins.
Explore the detector →Loops, repeated errors and activity that deserves a closer look.
Stuck loop
Catch the repeated action hiding inside a busy session.
Explore the detector →No progress
Spot long stretches of activity without a recorded edit or completion.
Explore the detector →Repeated tool failure
Find the failing step that retries keep burying.
Explore the detector →Action discrepancy
Notice when a failure is followed by a different action.
Explore the detector →Capacity refusals, unanswered requests and repeated restarts.
Rate limited
Separate capacity refusals from productive agent work.
Explore the detector →Blocked on user
Find the approval or unanswered question holding up a session.
Explore the detector →Repeated restarts
Spot a session that keeps starting over.
Explore the detector →Inspection incomplete
Know when credential inspection could not cover the full payload.
Explore the detector →Shared unusual actions across independent sessions.