Review agent · AI-agent security
Agent setup reviewer
Inventories the LLM-agent setup in your repo — agents, skills, memory, hooks, MCP servers, frameworks — and reviews it for prompt-injection, tool-safety and secrets risks.
Illustrative example of how the setup reviewer reads an agent config.
Why this agent matters
Repositories now contain instructions for AI agents: CLAUDE.md, AGENTS.md, skills, hooks that auto-approve commands, MCP servers with shell or network access. Those files decide what an agent is allowed to do on a developer's machine or in CI.
No code scanner reads them as a security surface. A hook that auto-approves shell commands, or an MCP server with an unrestricted file tool, is a real risk that ships with your code. This reviewer exists because nothing else looks there.
OpenRouting can also generate a safe, tailored setup for you — context files, skills, agents and conservative permissions — and open it as a pull request you review (50 credits).
What it detects
- Claude / Anthropic conventions: CLAUDE.md, AGENTS.md, .claude/ agents, skills, commands, settings and hooks, SKILL.md, memory files
- MCP server configs (mcp.json, .mcp.json, mcpServers blocks)
- Agent frameworks: LangChain, LangGraph, CrewAI, AutoGen, LlamaIndex, Semantic Kernel, Haystack, smolagents, Claude Agent SDK, OpenAI Agents SDK
- LLM SDKs: Anthropic, OpenAI, AWS Bedrock, Google Generative AI, Cohere, Mistral, LiteLLM, Ollama
What it reviews
- Prompt injection & tool safety — can untrusted input reach tools or agents; shell, file or network tools without allow-lists; hooks or settings that auto-approve dangerous actions
- Secrets & data exposure — credentials in agent or MCP config; secrets reachable by tools; memory files that may hold sensitive data
- Config hygiene — overly permissive permissions, unpinned models, auto-run commands, missing guardrails
Each risk comes with a severity, the file it's in, what is wrong with the actual config, and a specific recommendation. Results appear on the repository's Agent setup tab and in the security report.
Scope and limits
- It reports only what the configuration files actually show. It is instructed never to invent tools, config or secrets.
- A sound setup comes back with an empty or near-empty risk list rather than manufactured findings.
- Secret values are redacted before review; it runs read-only and never executes anything in your repo.
Common questions
When does the agent-setup review run?
During a full repository scan, if an LLM-agent setup is detected. It is an optional +10 credit add-on, charged only when the review actually runs.
Does it run my agents or MCP servers?
No. Detection and review are read-only. OpenRouting never executes code from your repository.
Related: AI / LLM safety agent · AI agent security use case · All review agents
Review your agent setup
100 free credits, no credit card. Runs automatically on full scans when a setup is detected.
Get started free