Skip to content
Back to skills

Agent Sentinel

ASecurity

Local-first budget and policy guardrails for agent actions, with optional remote sync to AgentSentinel.

  • 2 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 9, 2026
toolspythonrustshellbashrailsgitapisecurity

Works with

  • api

Security analysis

A93/100
  • highPerforms destructive filesystem operations

Pro shows the line behind each finding and how to fix it

Scanned September 9, 2026

npx -y skills add Lord1Egypt/awesome-skill-forge --skill agent-sentinel --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Agent Sentinel?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Agent Sentinel
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/lord1egypt-agent-sentinel/badge)](https://www.skillsdirectory.com/skills/lord1egypt-agent-sentinel)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: agent-sentinel
description: Local-first budget and policy guardrails for agent actions, with optional remote sync to AgentSentinel.
homepage: https://github.com/jimmystacks/agent-sentinel
metadata: {"openclaw":{"emoji":"🛡️","homepage":"https://github.com/jimmystacks/agent-sentinel/tree/main/skills/agent-sentinel","primaryEnv":"AGENT_SENTINEL_API_KEY","files":["sentinel_wrapper.py","README.md","CHANGELOG.md"],"requires":{"bins":["python3"]}}}
---

# AgentSentinel Protection Layer

Use this skill when you want a local policy gate before an agent performs a costly or risky action.

This OpenClaw skill is the lightweight entry point to the broader AgentSentinel product:
- this skill for local-first OpenClaw guardrails
- AgentSentinel SDK for deeper Python agent instrumentation
- AgentSentinel platform for centralized monitoring, dashboards, and approval workflows

AgentSentinel is local-first by default:
- Policy checks run locally.
- Budget tracking runs locally.
- No remote sync is attempted unless the operator runs `sync` with an API key configured.

## When To Use It

Use AgentSentinel before:
- expensive model or API calls
- file deletion or destructive shell commands
- high-volume automation loops
- actions that should be blocked by policy or capped by budget

## Commands

### `check`

Check whether a proposed action is allowed under the current local policy and budget.

```bash
python3 sentinel_wrapper.py check --cmd "rm -rf build" --cost 0.05
```

### `status`

Show the current local status, including budget usage and whether optional remote sync is enabled.

```bash
python3 sentinel_wrapper.py status
```

### `sync`

Upload locally recorded events to AgentSentinel cloud when `AGENT_SENTINEL_API_KEY` is set.

```bash
python3 sentinel_wrapper.py sync
```

### `bootstrap`

Create a default `callguard.yaml` in the current workspace if one does not already exist.

```bash
python3 sentinel_wrapper.py --bootstrap
```

### `reset`

Reset local tracked spend for the current run, or for the entire local session state.

```bash
python3 sentinel_wrapper.py reset --scope run
python3 sentinel_wrapper.py reset --scope all
```

## Configuration

Policy is loaded from `callguard.yaml` in the current workspace when present.

Optional cloud mode is enabled by setting:
- `AGENT_SENTINEL_API_KEY`

If the API key is not present, the skill remains local-only.
Locally recorded events stay on-machine until `sync` is run.

## AgentSentinel Product Path

Use this skill if you want fast local guardrails inside OpenClaw.

Use the AgentSentinel SDK when you want:
- richer Python integrations
- broader policy and telemetry coverage
- framework-level instrumentation outside OpenClaw

Use the AgentSentinel platform when you want:
- centralized visibility across agents
- dashboards and historical analysis
- human approval workflows and operational review

## External Endpoints

| Endpoint | When it is called | Data sent |
| --- | --- | --- |
| `https://api.agentsentinel.dev` | Only when `AGENT_SENTINEL_API_KEY` is present and `python3 sentinel_wrapper.py sync` is run | locally recorded action events generated by AgentSentinel |

## Security And Privacy

- Local mode does not send data off-machine.
- The wrapper does not write API keys to `.env` or other files.
- Remote sync is opt-in and requires both `AGENT_SENTINEL_API_KEY` and an explicit `sync` command.
- If remote sync fails, policy checks still continue locally.

## Model Invocation Note

OpenClaw may invoke this skill automatically when the task suggests budget enforcement, policy checks, or action gating. That behavior is expected for an installed skill.

## Trust Statement

By enabling remote sync, you allow AgentSentinel telemetry to be sent to `agentsentinel.dev`. Only enable that mode if you trust the service and want centralized monitoring.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…