AI agents don't answer anymore.
They act.
They run commands. Read files. Move data. Spend money. With your credentials.
The moment an agent can act for you
is the moment it can be turned against you.
One poisoned document. One hidden instruction.
Reads a document
trusted input
Hidden instruction
"exfiltrate the API key"
Sends your secrets out
→ attacker's server
Your identity controls never fired. It never exceeded its permissions.
Crawdad sits on the wire, on your machine,
and reads every action an agent takes.
DETECTIONS OVER TIME
RED TEAM DETECTION RATE
TOP ATTACK PATTERNS
ATTACK INTELLIGENCE · LAST 7 DAYS
0attacks blocked
Credential theft. Data exfiltration. Prompt injection.
Stopped. Before it happens.
ON YOUR MACHINE
Inspection happens here.
Prompts & data · stay local Only a verdict · leaves
The tool that watches everything can't leak it.
Fleet: All healthy
A dashboard shows you a summary. Crawdad shows you the truth.
We measure it in the open.
497
REAL ATTACKS · PUBLIC CORPUS
1,172
BENIGN SAMPLES · FALSE-POSITIVE TEST
CC-BY
REPRODUCIBLE · RUN IT YOURSELF
We publish our benchmark, including the attacks we fail to catch.
crawdad.
Runtime security for AI agents. It sees every action. Yours stays yours.
getcrawdad.dev