Your AI agents can call any tool.
Make sure they call the right ones.
Correctover authorizes every tool call before execution and produces cryptographically-signed evidence receipts after. Block SSRF, command injection, credential exfiltration, and prompt injection — without false-positive fatigue.
Keyword scanners don't understand context.
Most AI security tools either block legitimate operations (false positives) or miss real attacks (false negatives). They match patterns, not intent.
✕ Without Correctover
- ✕
exec()blocked everywhere — even in code-execution engines where it's expected - ✕
curl https://api.openai.comflagged as suspicious — breaking legitimate tool calls - ✕ Webshell uploads slip through because the scanner only checks file extensions
- ✕ Cloud metadata SSRF via
169.254.169.254not detected in agent network calls - ✕ No audit trail — you can't prove what an agent did or didn't do
✓ With Correctover
- ✓
exec()allowed in code-execution engines, blocked in file-write tools — context-aware - ✓ Public API calls pass through;
169.254.169.254and private IPs blocked - ✓ Webshells caught by content semantics —
<?php eval(...)?>in any file type - ✓ Every allow/block decision logged with a signed Ed25519 receipt
- ✓ Zero LLM calls — all checks are synchronous, sub-millisecond
Authorize before. Verify after.
Correctover sits between your agent and its tools. Every call goes through a three-phase pipeline:
Before execution
Tool name, arguments, and context checked against policy. SSRF, injection, and overprivilege detected.
During execution
Subprocess commands monitored. Dangerous patterns blocked in real time.
After execution
Output scanned for credential leaks and prompt injection. Signed receipt generated.
Six attack vectors. One guardrail.
Command Injection
Detects rm -rf, curl|sh, PowerShell IEX(DownloadString()), base64-encoded payloads, and chained commands — with tool-aware context to avoid blocking legitimate shell operations.
SSRF Prevention
Blocks requests to cloud metadata endpoints (169.254.169.254), private IP ranges, IPv4-mapped IPv6 bypass attempts, and DNS-rebinding patterns.
File Write Protection
Catches webshells, backdoors, and credential files regardless of extension. Understands code-block context in markdown to avoid false positives.
Credential Exfiltration
Scans tool output for API keys, private keys, and tokens. Blocks writes to world-readable paths and alerts on secrets in agent responses.
Prompt Injection
Detects indirect prompt injection in tool outputs — "ignore previous instructions", role hijacking, and encoded payloads — with tool-aware severity weighting.
Signed Evidence Receipts
Every allow/block decision produces an Ed25519-signed CCS receipt across the seven verification dimensions. The signature covers every field over RFC 8785 JCS and even binds the public key, its fingerprint, and the algorithm identifier — so anyone can verify it offline from the receipt alone. Prove what happened, when, and why.
Seven dimensions of runtime verification.
The CCS (Correctover Conformance Shape) defines what a verified agent output must contain. The specification is publicly archived on Zenodo.
To our knowledge, Correctover is the only field-level receipt in the AI agent tool-call setting that binds the public key, its fingerprint, and the signing-algorithm identifier inside the signature itself — defeating key-substitution and algorithm-downgrade attacks. Because the key travels inside the receipt, verification is fully offline, with no connection to us and no out-of-band key exchange.
Built on real vulnerability research.
CCS Runtime Verification — Technical Paper
Specification defining the 7-dimension verification framework for AI agent outputs. Currently under community review.
doi.org/10.5281/zenodo.21783723 →Tencent DSH Security Analysis (arXiv:2608.16393)
Independent research found indirect prompt injection success rates of 17–25.5% in DeepSeek Harness agents. Correctover's CCS Security dimension is the control layer for exactly this class of attack.
Read the analysis on Dev.to →MCP Server Vulnerability Disclosures
Documented SSRF, command injection, and credential exposure patterns across popular MCP server implementations. Findings shared responsibly with maintainers.
Run the scanner to check your config →Start free. Pay when you need proof.
The core SDK is free. The MCP Security Kit and audit reports are priced per engagement — reach out for a quote.
- Full runtime guardrail SDK
- Command injection + SSRF blocking
- Credential exfiltration detection
- CCS output validation
- DSH plugin included
- Zero runtime dependencies
- Everything in Open Source Core
- MCP Config Scanner
- Commercial license
- Ed25519 signed receipts
- Policy engine with custom rules
- Email support
- Full MCP server configuration audit
- MCP configuration security checks
- SSRF / injection / credential analysis
- Compliance certificate issued
- Remediation guidance
- Signed audit report
Secure your agents in 5 minutes.
No account required. No credit card. Just install and run.