GuardrailDoctor
Penetration-test your coding agent's guardrails before you ship.
What it does
Before you let an agent run with file and shell access, you want to know the guardrails actually hold. GuardrailDoctor probes the protections you have configured: it throws known attack patterns at your PreToolUse and PostToolUse hooks and your sensitive-file rules, then tells you which ones held and which let something through.
You get a pass or fail for each vector, the evidence behind the result, and a copy-paste fix for every gap it finds. It is a test harness, not a config change, so nothing about your setup is altered. You run it, you read the report, you patch what leaked.
What it checks
- Prompt-injection payloads aimed at your hook logic.
- Shell-command chaining that tries to slip past a single-command allowlist.
- Path-traversal attempts against sensitive-file protections.
- PreToolUse and PostToolUse hook coverage.
- 10+ attack vectors in total, each scored pass or fail.
- A report with evidence per vector and copy-paste remediation for every gap.
What the report looks like
Questions
What does it actually test?
Known attack patterns against the protections you have configured: prompt-injection, shell-chaining, and path-traversal aimed at your PreToolUse and PostToolUse hooks and your sensitive-file rules. It reports which vectors held and which let something through, across 10+ checks.
Will it change my agent configuration?
No. It assesses and reports. You get a pass or fail per vector with evidence and a copy-paste fix for each gap, which you apply yourself.
Which agents does it work with?
Any setup that reads SKILL.md and uses the PreToolUse/PostToolUse hook model, including Claude Code. Not locked to a single vendor.
Test your guardrails before something else does.
Current price and purchase option are shown on Agensi. Instant download. Works with any agent that reads SKILL.md.
Get GuardrailDoctor on Agensi