Observability & guardrails for the tools you already use.
Stop your AI agents from repeating the same mistakes.
AgentTrail traces your agent's execution and automatically compiles repeat failures into permanent guardrails.
npm i -g @agenttrail/guardSupports
- Claude Code
- Cursor
- Codex
From action to decision
See every action. Stop the wrong one before it runs.
AgentTrail traces what your agent does and puts a guardrail between its next action and your systems. The rule, the decision, and the reason stay together on the record.
Total visibility
Every session, every action, every dollar, across every agent you run.
Enforced guardrails
Captured patterns become rules that stop known failure modes before they merge.
Provable safety
Backtest your rules against real sessions before you turn them on in AgentTrail OS.
01 · Agent requests an action
Told "it's only dev data, just get it synced", the agent finds its schema push refused over 6 existing rows, and reaches for a reset.
npx prisma db push --force-reset02 · A guardrail matches
A flag that explicitly accepts data loss--force-resetwipes the database before it pushes the schema.03 · Decide before execution
Blocked before it ranThe rows survive. The agent stops and says the schema isn't synced yet.
From post-mortems to prevention
Every team has a post-mortem. Almost none of them become prevention.
An agent fails. Most teams document it and move on.
Without AgentTrail
- Post-mortems never become prevention
- Same mistakes repeat across agents
- Agents learn nothing between sessions
- Violations slip past review to prod
- No proof a guardrail actually works
With AgentTrail
- Repeat failures auto-captured as policies
- Outcomes generate policies automatically
- Risky actions blocked or held before they run
- Every session traced and searchable after the fact
- Backtests prove each rule on your real history
How it works
Make your agents better with every session
The AgentTrail OS workflow: observe what happened, prove the rule, then enforce it.
Observe
Trace every session: each action, tool call and dollar.
Detect
Repeat failures surface on their own, from your sessions.
Prove
Backtest a rule on your last 30 days before it's on.
Enforce
Block or hold the risky action before it runs.
Watch
See every hold, and the rule that fired.
Two products
Enforce on your machine. See every session in the cloud.
Two products for two jobs. AgentTrail Guard enforces rules right where your agent runs, with nothing to sign up for. AgentTrail OS keeps a searchable record of every session, what it cost, and what got held, whether you work solo or with a team.
AgentTrail Guard
Stops risky actions on your machine before they run. 74 guardrails, checked locally on every command and file change.
Learn more about AgentTrail GuardFor Codex CLI, also start Codex, type /hooks and approve each agenttrail-guard entry. Until you do, nothing is checked.
- Runs on
- Your machine
- Works with
- Claude Code, Cursor, Codex
- Account
- None needed
- License
- Apache 2.0
AgentTrail OS
One view of every agent you run, alone or as a team: what each one did, what it cost, and which rules held it. We host it for you.
Learn more about AgentTrail OS- Every session, searchable
- Repeat failures detected
- Rules backtested first
- Approvals and audit trail
- Runs on
- Hosted by AgentTrail
- Works with
- Claude Code, Cursor
- Account
- Personal or team workspace
- Pricing
- Per seat, starts free
OWASP Top 10s
Mapped to the OWASP risks for AI agents. Gaps included.
An item-by-item map of where AgentTrail stops the risk, where it only adds visibility, and where it doesn't help. We would rather show you the gaps than oversell the coverage.
AgentTrail is an independent project, not affiliated with or endorsed by OWASP.
Agentic Applications · 2026
2 direct · 6 partial · 1 work in progress · 1 out of scope
- ASI01 Agent Goal Hijack: Partial
- ASI02 Tool Misuse and Exploitation: Direct
- ASI03 Identity and Privilege Abuse: Partial
- ASI04 Agentic Supply Chain Vulnerabilities: Partial
- ASI05 Unexpected Code Execution: Direct
- ASI06 Memory and Context Poisoning: Work in progress
- ASI07 Insecure Inter-Agent Communication: Out of scope
- ASI08 Cascading Failures: Partial
- ASI09 Human-Agent Trust Exploitation: Partial
- ASI10 Rogue Agents: Partial
LLM Applications · 2026
3 direct · 2 partial · 3 work in progress · 2 out of scope
- LLM01 Prompt Injection: Work in progress
- LLM02 Sensitive Information Disclosure: Partial
- LLM03 Excessive Agency: Direct
- LLM04 Supply Chain: Partial
- LLM05 Data and Model Poisoning: Out of scope
- LLM06 Unbounded Consumption: Direct
- LLM07 Misinformation: Work in progress
- LLM08 Hidden Context Exposure: Work in progress
- LLM09 Vector and Embedding Weaknesses: Out of scope
- LLM10 Improper Output Handling: Direct
- Direct
- Partial
- Work in progress
- Out of scope
Stopped directly today
- ASI02Tool Misuse and Exploitation
- ASI05Unexpected Code Execution
- LLM03Excessive Agency
- LLM06Unbounded Consumption
- LLM10Improper Output Handling
Privacy & security
Transparent about your data, in both products.
AgentTrail Guard keeps everything on your machine. AgentTrail OS stores your agents' telemetry, encrypted, and never uses it to train shared models without your opt-in.
AgentTrail Guard
On your machine
Nothing leaves your machine unless you turn it on.
- Reads
- The command or file change your agent is about to make, so it can check it before it runs.
- Keeps
- A local log of matched calls, secrets scrubbed first. Capped at 1 MiB and 30 days, and you can clear it any time.
- Sends
- Nothing, by default. Crash reporting is opt-in, a scrubbed stack trace only, with nowhere to send until you set an endpoint.
AgentTrail OS
Hosted, for you or your team
Your agents' telemetry, not your codebase.
- Stores
- Agent telemetry: actions, tool calls, timing, tokens, cost and policy decisions. It never needs access to your source repositories.
- Protects
- TLS 1.2+ for the web app and API, encrypted at rest, and each workspace's data kept separate by org-scoped keys.
- Training
- No cross-customer models trained on your traces without your explicit opt-in.
- Encrypted in transit and at rest
- Deleted within 30 days of a request
- Every subprocessor named, with what it receives
AgentTrail OS
Stop babysitting your AI agents
Walk your team through AgentTrail OS with the people building it, and see how everyone's agent sessions become shared guardrails.
- Every agent session traced, with its cost
- Repeat failures caught and turned into rules
- Each rule backtested on your history first
AgentTrail OS · For teams
Bring your team. We'll bring the demo.
A walkthrough for engineering teams rolling out AI agents: shared guardrails, approvals, and one record of every session your team runs.
Just you? Skip the call. Install AgentTrail Guard in two commands.
