Detector libraryInspection incomplete

Inspection incomplete

A scan limit should be visible.

Know when credential inspection could not cover the full payload.

See the problem. Understand the finding.

English narration with captions.

How it gets overlooked

No credential warning appeared. Does that mean the whole payload was inspected? If the payload exceeded a scan limit, those are two different things. A useful monitoring system should make that gap visible.

Agent tools can produce very large arguments and outputs. ClawMetry keeps credential inspection bounded so one oversized payload cannot consume unlimited work. The important part is telling you when that bound was reached.

What ClawMetry detects

When a tool payload exceeds the bounded credential scan, ClawMetry raises an informational inspection incomplete finding. It records the number of limited payloads and the reasons. The contents do not need to be copied into the finding.

The difference that changes the finding

Triggering example

Oversized tool payload

Info finding

Quiet comparison

Ordinary tool payload

No finding for this detector.

In the checked example, an oversized command argument produces an informational coverage finding. An ordinary Git status argument stays quiet. This is evidence about the inspection boundary, not evidence that the oversized payload was malicious.

Inspect the detector result
{
  "kind": "inspection_incomplete",
  "severity": "info",
  "evidence": {
    "limited_payloads": 1,
    "reasons": [
      "input_size"
    ],
    "observed": "tool_arguments_and_results"
  }
}
Download inputs and complete results (JSON)
How the example was checked

These examples evaluate the published detector with authored event data or disposable configuration files. The videos illustrate those behaviors. They are not recordings of live agents or the product interface. No command in the examples was executed.

The result establishes behavior for these inputs. It does not establish runtime ingestion, prevention or a real compromise. Inspect the pinned source contract.

What to check next

Find the relevant tool activity and review the part of the workflow that produced the oversized content. Use an appropriate controlled review or a smaller input to answer the question the bounded scan could not settle. Keep the coverage gap visible until you have that evidence.

  1. Locate the limited payload
  2. Review its source and purpose
  3. Resolve the coverage gap

What this signal establishes

This finding concerns the credential scanner. It does not certify coverage of every detector or establish hostile intent.

Keep the important moments visible.

Follow agent activity, inspect findings and decide what needs your attention.