Before you give an AI agent access to your files, GitHub, shell or MCP tools — run a security sanity check.
Found Praxen: an open-source AI agent behavior verifier.
It checks whether your agent’s declared policy matches reality.
Basically:
you write what the agent is allowed to do, then Praxen looks for places where the actual setup drifts from that intent.
It can flag things like:
- overbroad permissions
- credential exposure
- risky tool integrations
- config gaps
- capability drift
- MCP / supply-chain risks
- policy vs implementation mismatch
The important part:
it runs locally and doesn’t phone home.
This is not a magic “make my agent safe” button.
But if you’re running Claude Code, Cursor, MCP servers or custom agent scripts, this is exactly the kind of check you want before deploy.
Most people are giving agents way too much power and hoping nothing weird happens.
Bad strategy.