AI agents don't answer anymore.
They
act
.
They run commands. Read files. Move data. Spend money. With your credentials.
The moment an agent can act for you
is the moment it can be turned
against
you.
One poisoned document. One hidden instruction.
Reads a document
trusted input
Hidden instruction
"exfiltrate the API key"
Sends your secrets out
→ attacker's server
Your identity controls never fired. It never exceeded its permissions.
Crawdad sits on the wire, on your machine,
and reads
every action
an agent takes.
DETECTIONS OVER TIME
RED TEAM DETECTION RATE
TOP ATTACK PATTERNS
ATTACK INTELLIGENCE · LAST 7 DAYS
0
attacks blocked
Credential theft. Data exfiltration. Prompt injection.
Stopped.
Before it happens.
ON YOUR MACHINE
Inspection happens here.
Prompts & data · stay local
Only a verdict · leaves
The tool that watches everything
can't leak it.
●
Fleet: All healthy
A dashboard shows you a summary. Crawdad shows you the
truth
.
We measure it in the open.
497
REAL ATTACKS · PUBLIC CORPUS
1,172
BENIGN SAMPLES · FALSE-POSITIVE TEST
CC-BY
REPRODUCIBLE · RUN IT YOURSELF
We publish our benchmark, including the attacks we
fail to catch.
crawdad
.
Runtime security for AI agents. It sees every action.
Yours stays yours.
getcrawdad.dev
🔇
↻ Replay