Observability & guardrails for the tools you already use.

Stop your AI agents from repeating the same mistakes.

AgentTrail traces your agent's execution and automatically compiles repeat failures into permanent guardrails.

bash
$npm i -g @agenttrail/guard

Supports

  • Claude Code
  • Cursor
  • Codex
Your code stays on your machine.What we collect

See every action. Stop the wrong one before it runs.

AgentTrail traces what your agent does and puts a guardrail between its next action and your systems. The rule, the decision, and the reason stay together on the record.

Why AgentTrail

Total visibility

Every session, every action, every dollar, across every agent you run.

Enforced guardrails

Captured patterns become rules that stop known failure modes before they merge.

Provable safety

Backtest your rules against real sessions before you turn them on in AgentTrail OS.

Action checkpointReal Claude Code session
  1. 01 · Agent requests an action

    Told "it's only dev data, just get it synced", the agent finds its schema push refused over 6 existing rows, and reaches for a reset.

    npx prisma db push --force-reset
  2. 02 · A guardrail matches

    A flag that explicitly accepts data loss

    --force-reset wipes the database before it pushes the schema.

  3. 03 · Decide before execution

    Blocked before it ran

    The rows survive. The agent stops and says the schema isn't synced yet.

Recorded in a demo repo. The agent's choices are its own.Read the case study

Every team has a post-mortem. Almost none of them become prevention.

An agent fails. Most teams document it and move on.

Without
AgentTrail
Failure
Post-mortem
CLAUDE.md
Forgotten
Repeats
Back to failure
With
Prevented
Loop closed

Without AgentTrail

  • Post-mortems never become prevention
  • Same mistakes repeat across agents
  • Agents learn nothing between sessions
  • Violations slip past review to prod
  • No proof a guardrail actually works

With AgentTrail

  • Repeat failures auto-captured as policies
  • Outcomes generate policies automatically
  • Risky actions blocked or held before they run
  • Every session traced and searchable after the fact
  • Backtests prove each rule on your real history

Make your agents better with every session

The AgentTrail OS workflow: observe what happened, prove the rule, then enforce it.

  1. Observe

    Trace every session: each action, tool call and dollar.

  2. Detect

    Repeat failures surface on their own, from your sessions.

  3. Prove

    Backtest a rule on your last 30 days before it's on.

  4. Enforce

    Block or hold the risky action before it runs.

  5. Watch

    See every hold, and the rule that fired.

Enforce on your machine. See every session in the cloud.

Two products for two jobs. AgentTrail Guard enforces rules right where your agent runs, with nothing to sign up for. AgentTrail OS keeps a searchable record of every session, what it cost, and what got held, whether you work solo or with a team.

Runs on your machineAvailable now

AgentTrail Guard

Stops risky actions on your machine before they run. 74 guardrails, checked locally on every command and file change.

Learn more about AgentTrail Guard
Two commands to set up
$ npm i -g @agenttrail/guard
$ agenttrail-guard init --agent claude
# or --agent cursor, --agent codex

For Codex CLI, also start Codex, type /hooks and approve each agenttrail-guard entry. Until you do, nothing is checked.

Runs on
Your machine
Works with
Claude Code, Cursor, Codex
Account
None needed
License
Apache 2.0
Hosted · solo or teamLaunching soon

AgentTrail OS

One view of every agent you run, alone or as a team: what each one did, what it cost, and which rules held it. We host it for you.

Learn more about AgentTrail OS
  • Every session, searchable
  • Repeat failures detected
  • Rules backtested first
  • Approvals and audit trail
Runs on
Hosted by AgentTrail
Works with
Claude Code, Cursor
Account
Personal or team workspace
Pricing
Per seat, starts free

Mapped to the OWASP risks for AI agents. Gaps included.

An item-by-item map of where AgentTrail stops the risk, where it only adds visibility, and where it doesn't help. We would rather show you the gaps than oversell the coverage.

See the full coverage matrix

AgentTrail is an independent project, not affiliated with or endorsed by OWASP.

Agentic Applications · 2026

2 direct · 6 partial · 1 work in progress · 1 out of scope

  1. ASI01 Agent Goal Hijack: Partial
  2. ASI02 Tool Misuse and Exploitation: Direct
  3. ASI03 Identity and Privilege Abuse: Partial
  4. ASI04 Agentic Supply Chain Vulnerabilities: Partial
  5. ASI05 Unexpected Code Execution: Direct
  6. ASI06 Memory and Context Poisoning: Work in progress
  7. ASI07 Insecure Inter-Agent Communication: Out of scope
  8. ASI08 Cascading Failures: Partial
  9. ASI09 Human-Agent Trust Exploitation: Partial
  10. ASI10 Rogue Agents: Partial

LLM Applications · 2026

3 direct · 2 partial · 3 work in progress · 2 out of scope

  1. LLM01 Prompt Injection: Work in progress
  2. LLM02 Sensitive Information Disclosure: Partial
  3. LLM03 Excessive Agency: Direct
  4. LLM04 Supply Chain: Partial
  5. LLM05 Data and Model Poisoning: Out of scope
  6. LLM06 Unbounded Consumption: Direct
  7. LLM07 Misinformation: Work in progress
  8. LLM08 Hidden Context Exposure: Work in progress
  9. LLM09 Vector and Embedding Weaknesses: Out of scope
  10. LLM10 Improper Output Handling: Direct
  • Direct
  • Partial
  • Work in progress
  • Out of scope

Stopped directly today

  • ASI02Tool Misuse and Exploitation
  • ASI05Unexpected Code Execution
  • LLM03Excessive Agency
  • LLM06Unbounded Consumption
  • LLM10Improper Output Handling

Transparent about your data, in both products.

AgentTrail Guard keeps everything on your machine. AgentTrail OS stores your agents' telemetry, encrypted, and never uses it to train shared models without your opt-in.

AgentTrail Guard

On your machine

Nothing leaves your machine unless you turn it on.

Reads
The command or file change your agent is about to make, so it can check it before it runs.
Keeps
A local log of matched calls, secrets scrubbed first. Capped at 1 MiB and 30 days, and you can clear it any time.
Sends
Nothing, by default. Crash reporting is opt-in, a scrubbed stack trace only, with nowhere to send until you set an endpoint.
Everything AgentTrail Guard reads, keeps and sends

AgentTrail OS

Hosted, for you or your team

Your agents' telemetry, not your codebase.

Stores
Agent telemetry: actions, tool calls, timing, tokens, cost and policy decisions. It never needs access to your source repositories.
Protects
TLS 1.2+ for the web app and API, encrypted at rest, and each workspace's data kept separate by org-scoped keys.
Training
No cross-customer models trained on your traces without your explicit opt-in.
Storage, encryption and compliance
  • Encrypted in transit and at rest
  • Deleted within 30 days of a request
  • Every subprocessor named, with what it receives
Security & Trust

Stop babysitting your AI agents

Walk your team through AgentTrail OS with the people building it, and see how everyone's agent sessions become shared guardrails.

  • Every agent session traced, with its cost
  • Repeat failures caught and turned into rules
  • Each rule backtested on your history first
View on GitHub

Bring your team. We'll bring the demo.

A walkthrough for engineering teams rolling out AI agents: shared guardrails, approvals, and one record of every session your team runs.

Just you? Skip the call. Install AgentTrail Guard in two commands.

No sales pitch. Just a walkthrough.