Review agent · AI-agent security

Agent setup reviewer

Inventories the LLM-agent setup in your repo — agents, skills, memory, hooks, MCP servers, frameworks — and reviews it for prompt-injection, tool-safety and secrets risks.

.claude/settings.json1{ "permissions": {2 "allow": ["Bash(*)"],3 "defaultMode":4 "bypassPermissions" } }Setupwhat this review answersTools that can reach the shell?Hooks or modes auto-approving?Secrets in agent or MCP config?$ verdict REAL ISSUE$ fix scope tools, keep approvals on▍

Illustrative example of how the setup reviewer reads an agent config.

Why this agent matters

Repositories now contain instructions for AI agents: CLAUDE.md, AGENTS.md, skills, hooks that auto-approve commands, MCP servers with shell or network access. Those files decide what an agent is allowed to do on a developer's machine or in CI.

No code scanner reads them as a security surface. A hook that auto-approves shell commands, or an MCP server with an unrestricted file tool, is a real risk that ships with your code. This reviewer exists because nothing else looks there.

OpenRouting can also generate a safe, tailored setup for you — context files, skills, agents and conservative permissions — and open it as a pull request you review (50 credits).

What it detects

  • Claude / Anthropic conventions: CLAUDE.md, AGENTS.md, .claude/ agents, skills, commands, settings and hooks, SKILL.md, memory files
  • MCP server configs (mcp.json, .mcp.json, mcpServers blocks)
  • Agent frameworks: LangChain, LangGraph, CrewAI, AutoGen, LlamaIndex, Semantic Kernel, Haystack, smolagents, Claude Agent SDK, OpenAI Agents SDK
  • LLM SDKs: Anthropic, OpenAI, AWS Bedrock, Google Generative AI, Cohere, Mistral, LiteLLM, Ollama

What it reviews

  • Prompt injection & tool safety — can untrusted input reach tools or agents; shell, file or network tools without allow-lists; hooks or settings that auto-approve dangerous actions
  • Secrets & data exposure — credentials in agent or MCP config; secrets reachable by tools; memory files that may hold sensitive data
  • Config hygiene — overly permissive permissions, unpinned models, auto-run commands, missing guardrails

Each risk comes with a severity, the file it's in, what is wrong with the actual config, and a specific recommendation. Results appear on the repository's Agent setup tab and in the security report.

Scope and limits

  • It reports only what the configuration files actually show. It is instructed never to invent tools, config or secrets.
  • A sound setup comes back with an empty or near-empty risk list rather than manufactured findings.
  • Secret values are redacted before review; it runs read-only and never executes anything in your repo.

Common questions

When does the agent-setup review run?

During a full repository scan, if an LLM-agent setup is detected. It is an optional +10 credit add-on, charged only when the review actually runs.

Does it run my agents or MCP servers?

No. Detection and review are read-only. OpenRouting never executes code from your repository.

Related: AI / LLM safety agent · AI agent security use case · All review agents

Review your agent setup

100 free credits, no credit card. Runs automatically on full scans when a setup is detected.

Get started free