Run a full AgentKeeper security audit of your Claude Code environment. Covers setup compliance, secret scanning, and plugin supply chain inspection in one unified report with a letter grade. Use when the user wants to check their security posture, run a security audit, or asks about security issues.
Connect AgentKeeper to this workstation. Supports interactive device-code browser flow (no args) or headless --api-key for CI, managed laptops, and fleet provisioning. Run when the user wants to authenticate, link their account, set up an API key, or paste an existing key.
Remove AgentKeeper hooks and API key. Run when the user wants to unlink their account, remove hooks from settings.json, or clean up before uninstalling the plugin.
Audit all installed Claude Code plugins, skills, hooks, and MCP servers for malicious behavior. Checks for prompt injection, data exfiltration, credential theft, obfuscated code, and supply chain attacks. This is the plugin ecosystem security scanner. Run when the user wants to verify their installed plugins are safe.
View organization security policies for AgentKeeper. Shows detection mode, blocked tools, blocked commands, path restrictions, and custom blocklists. Run when the user wants to see what policies are enforced, check security settings, or view org configuration.
Summarize the current Claude Code session from a security perspective. Shows tool call counts, files modified, bash commands run, and threats detected. Run when the user wants to review what happened during their session.
Run the AgentKeeper security scanner on the current host. Checks for macOS/Linux security misconfigurations, network settings, and prerequisites. Run when the user wants a full host security scan.
Scan the current working directory for exposed secrets, API keys, private keys, database credentials, and hardcoded tokens. Run when the user wants to find leaked credentials or check for secret exposure in their project. Never prints actual secret values.
Guided onboarding for AgentKeeper. Run when the user wants to configure AgentKeeper, check their current mode (local/connected/push-hooks), enable or disable blocking mode, or get started with the plugin.
Show AgentKeeper shield status including connection mode, threat statistics, and workstation info. Run when the user wants to see if AgentKeeper is active, check their connection, or view threat stats.