Features / Tool security

Check your tools. Choose how you review.

Combine quarantine, tool-change review, offline scanning, sensitive-data detection, and schema checks.

Why it matters

More intention.
Less guesswork.

A tool definition can change after approval. A response can contain unexpected data. Put explicit checks along the path from discovery to execution.

01

Quarantine & rug-pull protection

With tool quarantine enabled, new or changed tools after the trusted baseline are held for review.

02

Your choice of review

Manual inspection is not required for every tool. Use the TPA scanner or ask your AI agent to review quarantined tool definitions and findings. Review assistance does not bypass approval controls.

03

Offline tool scanner

The built-in deterministic engine checks tool definitions locally, without Docker, an LLM, or a network request. Optional deep scanners add separate checks.

04

Sensitive-data detection

Flag potential secrets in tool arguments and responses for review in the activity log.

05

Output schema validation

Check structured responses against a tool’s declared output schema. Choose warning or strict rejection behavior.

An example workflow

A trusted tool changes. Choose how to review it.

  1. Establish a trusted baseline with tool quarantine enabled.
  2. A later tool-definition change is held for review.
  3. Use the TPA scanner, ask your agent to review the quarantined definition and findings, or inspect the diff yourself. Configured approval controls still apply.

Where the boundary is

Definition-change detection does not detect every implementation change. Scanners can miss threats or flag benign content. Output validation defaults to warnings and requires a declared schema.

Explore the rest of your setup