One GitHub write, honestly scoped.
AgentGuard currently has dated evidence for one named action on a same-UID install. That is configured intercept. It is not capability isolation, and it is not a firewall result.
Named action
Operation github.create_or_update_file against a repository file. The broker wraps a construction-time stdio child: frozen command, argv, and cwd. The GitHub App installation token is minted at spawn and is not in the MCP request.
- Current packages:
@the-bot-club/agentguard@0.11.2andagentguard-tech==0.11.2 - Upstream image
ghcr.io/github/github-mcp-server@sha256:46cdbbd810faf6f7aed1745ea04057443f5cb9fcadc15c7308add18cf9a83e33 - Broker tarball SHA-256
70daaae891ad749d8f03a26a7532d20a8b46588c45de37fbc0002823f83bf40d - Allow proof on
thebotclub/agentguard-webmain:named-action-proof-broker.txt, blobab9d05fceeeee27a253aa8343ca36e55ad3c65c4 - Deny proof: the same path
named-action-proof-deny.txtwas not created (GitHub 404; adapter writes 0; docker not started) - Owned OpenClaw fleet:
mcp.servers.agentguard-githubcommand is the broker wrap; the unwrappedgithub-mcp-stdiocommand was deleted. HTTPautoclaw-githubstays off. OpenClaw MCP doctor:agentguard-github: ok. - Fleet unwrapped step
named-action-proof-fleet-stdio.txtsha575aa0a39c7233534e9f6ede3f3ca56bb87a1d43; after replacenamed-action-proof-fleet-broker.txtsha9da6c5eea1a73901a6db696c2e821703648a2c3c
Assurance tier actually earned
Configured intercept. Same-UID mcp.servers.*.command replace. The agent can still spawn the upstream binary, rewrite config, and use native tools unless those are separately denied.
Capability isolation is not claimed. There is no dedicated broker user, and OpenClaw can still read the same home directory.
Bypass matrix
- Same-UID exec / config rewrite. Bypass of this wrap. Not a host-isolation failure because isolation was not claimed.
- Disabled OpenClaw hook. Bypass of compatibility telemetry only. The named wrap is a stdio command replace, not a hook.
- Native OpenClaw
exec,browser,write. Uncovered. - HTTP MCP
autoclaw-githubandautoclaw-productivity. Uncovered. This wrap does not proxy Streamable HTTP. - Host / admin / kernel compromise. Out of scope.
What this page does not say
No regulator outcome, no CPS 230, no EU AI Act conformity, no production-proven category claim, and no statement that OpenClaw cannot act. The trust page still describes firewall proof as pending.