How it gets overlooked
You recognize the agent. Do you recognize everything it can load now? An MCP server, skill or plugin can appear after the agent environment was last reviewed.
The change might be an intentional upgrade or a new integration. It might also be unexpected. Without an inventory over time, both look like part of the current setup, and the moment they changed is easy to lose.
What ClawMetry detects
ClawMetry inventories supported agent components and compares them with the existing baseline. A new component or a changed content hash can raise an agent component change warning for relevant sessions. The finding identifies the component and the kind of change.
The difference that changes the finding
Triggering example
MCP server added later
Warning finding
Quiet comparison
First inventory baseline
No finding for this detector.
In the checked example, a new MCP server after the baseline produces a warning. The first inventory stays quiet, because everything being new to the observer is not the same as a new change. Unchanged components also do not create fresh change findings.
Inspect the detector result
{
"kind": "agent_component_change",
"severity": "warning",
"evidence": {
"observed": "agent_inventory",
"components": [
{
"kind": "mcp_server",
"name": "review-server",
"scope": "global",
"source": ".claude.json",
"change": "new",
"changed_at": 1800000000000,
"version": "",
"content_hash": "aaaaaaaaaaaa",
"previous_hash": "",
"readers": [
"claude_code"
]
}
],
"count": 1
}
}Download inputs and complete results (JSON)How the example was checked
These examples evaluate the published detector with authored event data or disposable configuration files. The videos illustrate those behaviors. They are not recordings of live agents or the product interface. No command in the examples was executed.
The result establishes behavior for these inputs. It does not establish runtime ingestion, prevention or a real compromise. Inspect the pinned source contract.
What to check next
Compare the change with your intended agent setup. Review the component source, version and capabilities. Check which runtime and workspace load it, then decide whether the sessions using it should continue with that configuration.
- Check the component source
- Review the intended version
- Identify affected sessions
What this signal establishes
Inventory changes are not a malware verdict. The detector needs readable supported configuration and a prior baseline to identify later changes.