Detector libraryAgent component change

Agent component change

A new tool joined the agent.

Track added or changed MCP servers, skills and plugins.

See the problem. Understand the finding.

English narration with captions.

How it gets overlooked

You recognize the agent. Do you recognize everything it can load now? An MCP server, skill or plugin can appear after the agent environment was last reviewed.

The change might be an intentional upgrade or a new integration. It might also be unexpected. Without an inventory over time, both look like part of the current setup, and the moment they changed is easy to lose.

What ClawMetry detects

ClawMetry inventories supported agent components and compares them with the existing baseline. A new component or a changed content hash can raise an agent component change warning for relevant sessions. The finding identifies the component and the kind of change.

The difference that changes the finding

Triggering example

MCP server added later

Warning finding

Quiet comparison

First inventory baseline

No finding for this detector.

In the checked example, a new MCP server after the baseline produces a warning. The first inventory stays quiet, because everything being new to the observer is not the same as a new change. Unchanged components also do not create fresh change findings.

Inspect the detector result
{
  "kind": "agent_component_change",
  "severity": "warning",
  "evidence": {
    "observed": "agent_inventory",
    "components": [
      {
        "kind": "mcp_server",
        "name": "review-server",
        "scope": "global",
        "source": ".claude.json",
        "change": "new",
        "changed_at": 1800000000000,
        "version": "",
        "content_hash": "aaaaaaaaaaaa",
        "previous_hash": "",
        "readers": [
          "claude_code"
        ]
      }
    ],
    "count": 1
  }
}
Download inputs and complete results (JSON)
How the example was checked

These examples evaluate the published detector with authored event data or disposable configuration files. The videos illustrate those behaviors. They are not recordings of live agents or the product interface. No command in the examples was executed.

The result establishes behavior for these inputs. It does not establish runtime ingestion, prevention or a real compromise. Inspect the pinned source contract.

What to check next

Compare the change with your intended agent setup. Review the component source, version and capabilities. Check which runtime and workspace load it, then decide whether the sessions using it should continue with that configuration.

  1. Check the component source
  2. Review the intended version
  3. Identify affected sessions

What this signal establishes

Inventory changes are not a malware verdict. The detector needs readable supported configuration and a prior baseline to identify later changes.

Keep the important moments visible.

Follow agent activity, inspect findings and decide what needs your attention.