Operate · Coding agents
Secure what your coding agents are told, run and change.
Heeler flags risky actions in agent sessions, blocks risky agent files at the pull request, and traces production back to the prompt.
Every coding agent, on every machine.
The Workstation Sensor reports the agents, skills, MCP servers and hooks on each machine.
Skills, hooks and MCP configs, scored.
Every agent file gets a safety score from 0 to 100 and an assessed intent.
Catch risky agent actions at the step they happen.
Heeler checks every step of an agent session: the commands it runs, the output it reads, and whether the developer asked for it.
Trace what is running back to the prompt that built it.
Pick any service running in production. Heeler shows the image, commit, agent session, prompt and developer behind it.
How it deploys
In the repo, from pull request on.
Identify risky agent files in your repos.
Heeler evaluates each connected repository for the files your agents follow.
- Scan each repository
- Find instructions, skills, hooks and MCP config
- Score each file 0 to 100. Below 70 is At Risk
Files · acme · At Risk first
- .claude/skills/deploy42 · Suspicious
- .cursor/mcp.json64 · At Risk
- AGENTS.md96 · Benign
Gate new and changed agent files on the pull request.
Observe, warn or block. The same check runs in CI.
Explore PR Guardrailsacme/payments-api · PR #512 · Heeler Guardrail
- Agent File Rated Suspicious · deploy/SKILL.mdBlock
- Agent File Introduced · .cursor/mcp.jsonWarn
- heelercli ci --checks agent-filesCI
Route each new at-risk agent file to its owner.
A workflow posts to Slack or opens a Jira, Linear or GitHub ticket.
Explore Autonomous OperationsWorkflow · At-Risk Agent File
- WhenNew At-Risk Agent File
- SlackSafety score: 42/100
- TicketJira, Linear or GitHub
The same score for agent files, wherever Heeler finds them.
Show the evidence behind each score.
Rules, a model's read of intent, and the hosts it reaches. Same content, same score.
.claude/skills/deploy/SKILL.md · line 14
- Static Risk · Insecure Shell PipeHigh
- LLM Risk · Remote Code ExecutionHigh
- External Risk · get.acme-tools.ioUnrecognized
Where Heeler meets the coding agent.
Purpose-built for the AI SDLC
