Use case
Secure your AI-agent setup
Teams ship LLM agents faster than they review them. OpenRouting finds the over-permissive configuration that turns prompt injection into real actions.
Illustrative example of an over-permissive agent setting.
In short: OpenRouting finds the AI-agent configuration in your repository (CLAUDE.md, .claude/ agents and skills, MCP configs, agent frameworks) and has Claude review it for prompt injection, over-broad tools and exposed secrets, with a concrete fix for each issue.
The risk grows with what the agent can do
An agent that only summarizes text is low-risk. An agent with a shell tool, file-write access, or the ability to open pull requests is a different story: text it ingests can carry instructions, and those instructions become actions.
Most real exposure comes from a handful of over-permissive settings — a read tool that can reach your secrets, a deny-list that misses an equivalent command, a hook that auto-approves dangerous actions. Those are findable.
What OpenRouting detects
During a scan, OpenRouting inventories your agent setup across four kinds:
- Claude/Anthropic conventions: CLAUDE.md, AGENTS.md, .claude agents, skills, commands, settings/hooks, and memory.
- Agent frameworks: LangChain/LangGraph, CrewAI, AutoGen, LlamaIndex, and agent SDKs.
- LLM SDK usage across your dependency files.
- MCP servers and tool configurations.
What the review looks for
Claude reviews the detected setup for prompt-injection and tool safety (over-broad tool permissions, unscoped shell or file tools, auto-approved actions), secrets and data exposure (credentials in config, secrets reachable by tools, sensitive memory), and configuration hygiene (unpinned models, permissive hooks, deny-lists that can be bypassed).
You get a plain inventory plus specific findings with fixes — and for a deeper engagement, the option to request a human expert review.
Questions
What is an AI-agent setup?
The code and configuration that builds or runs LLM agents: agent definitions, skills, memory stores, tool and MCP server configurations, and the hooks or permission files that wire them together.
How does OpenRouting review it?
During a scan, OpenRouting inventories the agent setup and has Claude review it for prompt-injection and tool-safety risks, secrets exposure, and configuration hygiene — returning specific findings with recommended fixes.
Can I get a human expert review?
Yes. From the agent-setup panel you can request a human expert review — a general audit or an incident response — and our team follows up on scope.