Use case

Secure your AI-agent setup

Teams ship LLM agents faster than they review them. OpenRouting finds the over-permissive configuration that turns prompt injection into real actions.

.claude/settings.json1{ "permissions": {2 "allow": ["Bash(*)"],3 "defaultMode":4 "bypassPermissions" } }Setupwhat this review answersTools that can reach the shell?Hooks or modes auto-approving?Secrets in agent or MCP config?$ verdict REAL ISSUE$ fix scope tools, keep approvals on▍

Illustrative example of an over-permissive agent setting.

In short: OpenRouting finds the AI-agent configuration in your repository (CLAUDE.md, .claude/ agents and skills, MCP configs, agent frameworks) and has Claude review it for prompt injection, over-broad tools and exposed secrets, with a concrete fix for each issue.

The risk grows with what the agent can do

An agent that only summarizes text is low-risk. An agent with a shell tool, file-write access, or the ability to open pull requests is a different story: text it ingests can carry instructions, and those instructions become actions.

Most real exposure comes from a handful of over-permissive settings — a read tool that can reach your secrets, a deny-list that misses an equivalent command, a hook that auto-approves dangerous actions. Those are findable.

What OpenRouting detects

During a scan, OpenRouting inventories your agent setup across four kinds:

  • Claude/Anthropic conventions: CLAUDE.md, AGENTS.md, .claude agents, skills, commands, settings/hooks, and memory.
  • Agent frameworks: LangChain/LangGraph, CrewAI, AutoGen, LlamaIndex, and agent SDKs.
  • LLM SDK usage across your dependency files.
  • MCP servers and tool configurations.

What the review looks for

Claude reviews the detected setup for prompt-injection and tool safety (over-broad tool permissions, unscoped shell or file tools, auto-approved actions), secrets and data exposure (credentials in config, secrets reachable by tools, sensitive memory), and configuration hygiene (unpinned models, permissive hooks, deny-lists that can be bypassed).

You get a plain inventory plus specific findings with fixes — and for a deeper engagement, the option to request a human expert review.

Get started free

Questions

What is an AI-agent setup?

The code and configuration that builds or runs LLM agents: agent definitions, skills, memory stores, tool and MCP server configurations, and the hooks or permission files that wire them together.

How does OpenRouting review it?

During a scan, OpenRouting inventories the agent setup and has Claude review it for prompt-injection and tool-safety risks, secrets exposure, and configuration hygiene — returning specific findings with recommended fixes.

Can I get a human expert review?

Yes. From the agent-setup panel you can request a human expert review — a general audit or an incident response — and our team follows up on scope.