Named-action proof

One GitHub write, honestly scoped.

AgentGuard currently has dated evidence for one named action on a same-UID install. That is configured intercept. It is not capability isolation, and it is not a firewall result.

Named action

Operation github.create_or_update_file against a repository file. The broker wraps a construction-time stdio child: frozen command, argv, and cwd. The GitHub App installation token is minted at spawn and is not in the MCP request.

  • Current packages: @the-bot-club/agentguard@0.11.2 and agentguard-tech==0.11.2
  • Upstream image ghcr.io/github/github-mcp-server@sha256:46cdbbd810faf6f7aed1745ea04057443f5cb9fcadc15c7308add18cf9a83e33
  • Broker tarball SHA-256 70daaae891ad749d8f03a26a7532d20a8b46588c45de37fbc0002823f83bf40d
  • Allow proof on thebotclub/agentguard-web main: named-action-proof-broker.txt, blob ab9d05fceeeee27a253aa8343ca36e55ad3c65c4
  • Deny proof: the same path named-action-proof-deny.txt was not created (GitHub 404; adapter writes 0; docker not started)
  • Owned OpenClaw fleet: mcp.servers.agentguard-github command is the broker wrap; the unwrapped github-mcp-stdio command was deleted. HTTP autoclaw-github stays off. OpenClaw MCP doctor: agentguard-github: ok.
  • Fleet unwrapped step named-action-proof-fleet-stdio.txt sha 575aa0a39c7233534e9f6ede3f3ca56bb87a1d43; after replace named-action-proof-fleet-broker.txt sha 9da6c5eea1a73901a6db696c2e821703648a2c3c

Assurance tier actually earned

Configured intercept. Same-UID mcp.servers.*.command replace. The agent can still spawn the upstream binary, rewrite config, and use native tools unless those are separately denied.

Capability isolation is not claimed. There is no dedicated broker user, and OpenClaw can still read the same home directory.

Bypass matrix

  • Same-UID exec / config rewrite. Bypass of this wrap. Not a host-isolation failure because isolation was not claimed.
  • Disabled OpenClaw hook. Bypass of compatibility telemetry only. The named wrap is a stdio command replace, not a hook.
  • Native OpenClaw exec, browser, write. Uncovered.
  • HTTP MCP autoclaw-github and autoclaw-productivity. Uncovered. This wrap does not proxy Streamable HTTP.
  • Host / admin / kernel compromise. Out of scope.

What this page does not say

No regulator outcome, no CPS 230, no EU AI Act conformity, no production-proven category claim, and no statement that OpenClaw cannot act. The trust page still describes firewall proof as pending.